Return-Path: Delivered-To: apmail-httpd-docs-archive@httpd.apache.org Received: (qmail 68508 invoked by uid 500); 7 Jun 2003 05:50:52 -0000 Mailing-List: contact docs-help@httpd.apache.org; run by ezmlm Precedence: bulk list-help: list-unsubscribe: list-post: Reply-To: docs@httpd.apache.org Delivered-To: mailing list docs@httpd.apache.org Received: (qmail 68485 invoked by uid 500); 7 Jun 2003 05:50:52 -0000 Delivered-To: apmail-apache-docs@apache.org Delivered-To: apmail-httpd-docs-1.3-cvs@apache.org Date: 7 Jun 2003 05:50:50 -0000 Message-ID: <20030607055050.42109.qmail@icarus.apache.org> From: jsl@apache.org To: httpd-docs-1.3-cvs@apache.org Subject: cvs commit: httpd-docs-1.3/htdocs/manual/misc security_tips.html X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N jsl 2003/06/06 22:50:50 Modified: htdocs/manual/misc security_tips.html Log: Typo/spelling/grammar corrections. Revision Changes Path 1.33 +4 -4 httpd-docs-1.3/htdocs/manual/misc/security_tips.html Index: security_tips.html =================================================================== RCS file: /home/cvs/httpd-docs-1.3/htdocs/manual/misc/security_tips.html,v retrieving revision 1.32 retrieving revision 1.33 diff -u -r1.32 -r1.33 --- security_tips.html 29 Apr 2003 08:34:06 -0000 1.32 +++ security_tips.html 7 Jun 2003 05:50:50 -0000 1.33 @@ -51,8 +51,8 @@ directive to serve hits. As is the case with any command that root executes, you must take care that it is protected from modification by non-root users. Not only must the files - themselves be writeable only by root, but so must the - directories, and parents of all directories. For example, if + themselves be writeable only by root, but also the + directories and parents of all directories. For example, if you choose to place ServerRoot in /usr/local/apache then it is suggested that you create that directory as root, with commands like these:

@@ -130,12 +130,12 @@ of risk.

Another solution is to disable the ability to run scripts - and programs from SSI pages. To do this replace + and programs from SSI pages. To do this, replace Includes with IncludesNOEXEC in the Options directive. Note that users may still use <--#include virtual="..." --> to execute CGI scripts if these scripts are in directories - desginated by a ScriptAlias directive.


--------------------------------------------------------------------- To unsubscribe, e-mail: docs-unsubscribe@httpd.apache.org For additional commands, e-mail: docs-help@httpd.apache.org