httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From David Landin <dlan...@evcom.net>
Subject [users@httpd] DirectoryIndex Circumvents -FollowSymLinks?
Date Wed, 30 Oct 2002 21:28:42 GMT
Using apache 2.0.43, and given the httpd.conf below, if I make
/home/www/index.html a symbolic link to /home/www/foo.html, a request
for http://localhost/index.html predictably fails with a "403 Forbidden"
error and generates a "Symbolic link not allowed: /home/www/index.html"
message in the error log.  However, a request for http://localhost/
returns /home/www/foo.html.  This behavior seems to me inconsistent and
potentially dangerous.  Am I missing something?

Dave

# /etc/httpd/conf/httpd.conf

Group			www
Listen			80
LogLevel		info
PidFile			/var/run/httpd.pid
ServerRoot		/etc/httpd
User			www

LoadModule		dir_module	mods/mod_dir.so
LoadModule		mime_module	mods/mod_mime.so

DirectoryIndex		index.html
TypesConfig		conf/mime.types

<Directory />
	AllowOverride	None
	Options		None
</Directory>

ServerName		localhost
DocumentRoot		/home/www

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message