Return-Path: Delivered-To: apmail-httpd-users-archive@www.apache.org Received: (qmail 72363 invoked from network); 15 Jul 2004 12:11:35 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (209.237.227.199) by minotaur-2.apache.org with SMTP; 15 Jul 2004 12:11:35 -0000 Received: (qmail 23099 invoked by uid 500); 15 Jul 2004 12:11:17 -0000 Delivered-To: apmail-httpd-users-archive@httpd.apache.org Received: (qmail 23088 invoked by uid 500); 15 Jul 2004 12:11:17 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: list-post: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 23074 invoked by uid 99); 15 Jul 2004 12:11:17 -0000 X-ASF-Spam-Status: No, hits=0.0 required=10.0 tests= X-Spam-Check-By: apache.org Received: from [62.190.237.98] (HELO usercf098.dsl.pipex.com) (62.190.237.98) by apache.org (qpsmtpd/0.27.1) with ESMTP; Thu, 15 Jul 2004 05:11:14 -0700 Received: from [192.168.7.2] (helo=[192.168.7.2]) by usercf098.dsl.pipex.com with asmtp (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.34) id 1Bl561-00055f-MB for users@httpd.apache.org; Thu, 15 Jul 2004 12:12:17 +0000 Message-ID: <40F6745A.8030906@thelight.org.uk> Date: Thu, 15 Jul 2004 13:11:06 +0100 From: Simon Reply-To: admin@thelight.org.uk Organization: thelight User-Agent: Mozilla Thunderbird 0.7.1 (Windows/20040626) X-Accept-Language: en-us, en MIME-Version: 1.0 To: users@httpd.apache.org References: <40F5891F.8090701@thelight.org.uk> In-Reply-To: Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=sha1; boundary="------------ms040307090707090805030106" X-added: This email was sent via TheLight mail server X-added: Rules are available at http://mail.thelight.org.uk/rules.html X-added: If you believe this email was sent in violation of the rules X-added: Please email abuse@thelight.org.uk with appropriate information X-Virus-Checked: Checked Subject: Re: [users@httpd] server-status / server-info protection X-Spam-Rating: minotaur-2.apache.org 1.6.2 0/1000/N --------------ms040307090707090805030106 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Joshua Slive wrote: > On Wed, 14 Jul 2004 20:27:27 +0100, Simon wrote: > >>Im trying to restrict my server-info and server-status pages to >>localhost only using the following lines: >> >> >> SetHandler server-info >> Order Deny,Allow >> Deny from all >> Allow from 127.0.0.1 >> >> >> SetHandler server-status >> Order Deny,Allow >> Deny from all >> Allow from 127.0.0.1 >> >> >>The problem is that for some reason, I can still access these pages from >>outside localhost. Are these lines correct/all that I need? > > > Yes, they are correct. > > Are you sure you are editting the right config file? > > Have you restarted the server after making changes? > > Are there any other sections that might be overriding these ones? > > Are client requests really arriving from outside, or do you have a > proxy on your local computer that is forwarding to apache? (For > example, on Mac OSX, all requests look like they come from localhost > because of a local proxy.) > > Joshua. > Thanks. It was being over-ridden by another section later in the config file. Moving the server-status/server-info elements to underneath the other section solved the problem. --------------ms040307090707090805030106 Content-Type: application/x-pkcs7-signature; name="smime.p7s" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="smime.p7s" Content-Description: S/MIME Cryptographic Signature MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIJjjCC BMMwggKroAMCAQICAwCcaDANBgkqhkiG9w0BAQQFADB5MRAwDgYDVQQKEwdSb290IENBMR4w HAYDVQQLExVodHRwOi8vd3d3LmNhY2VydC5vcmcxIjAgBgNVBAMTGUNBIENlcnQgU2lnbmlu ZyBBdXRob3JpdHkxITAfBgkqhkiG9w0BCQEWEnN1cHBvcnRAY2FjZXJ0Lm9yZzAeFw0wNDA3 MDkxMjIxMDFaFw0wNTA3MDkxMjIxMDFaMEExGTAXBgNVBAMTEENBY2VydCBVc2VyIENlcnQx JDAiBgkqhkiG9w0BCQEWFWFkbWluQHRoZWxpZ2h0Lm9yZy51azCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAM21uVL7G/yQtZMMaaez3nPYeXOYswrqe8mJsrGlTBy+MnPSw/F1 SNTplTMOl1Mqqk5WMURO/e95pPoAOSaYnePNp4VE0gmfk8kdercRkVUJfSCBcKrm4wcvTOMN MUYG8lFVkMrp1VsYoKNfTxHO5bzkyI2MhTynBczTdN/cmfTWp4ulJHLE20dxiYaR4rbs2SQu 6G2aLrsBxGZdY7shETI1g0P0dKIcKBjI7kYs0/PMS3jvizcqRkaA9wrpo1k9BY+Cuj1CnMhs ddddE8NzgxAHpl9H3ptvA7HITTaFcFi0qzYtQI4NnKGYGa+5wMmogPlp3vtJ0buBLjW3fh35 d6kCAwEAAaOBizCBiDAMBgNVHRMBAf8EAjAAMFYGCWCGSAGG+EIBDQRJFkdUbyBnZXQgeW91 ciBvd24gY2VydGlmaWNhdGUgZm9yIEZSRUUgaGVhZCBvdmVyIHRvIGh0dHA6Ly93d3cuY2Fj ZXJ0Lm9yZzAgBgNVHREEGTAXgRVhZG1pbkB0aGVsaWdodC5vcmcudWswDQYJKoZIhvcNAQEE BQADggIBAK7/m0XDwAEWiF/g2ONsPeb0lNJCda6R51b1Y+EVqpSh8DGKzS4k7R/tREZcaHnW rYmBCStgNfTk8FcdgJiL21+uF/0kBSocjwZZGwj/Whsw00s3x36k5bHmHDgrBVg6p6fg3KxH 2EHS79UPeyJo/8PzN1b8P1Hh5fsH+DpyqCwXsmG2c7ORUE4xp2V65YcB6hPUSUD+5k1lbQyx N3yd5Ez3nTUuOIQLkyROGuqLTTCNbe0pARSlruaN+h9hEMtbQxwXN2jC76HL3PLZUKfCTaI6 pyK/S/qWB8yLAheKkgGG1RCzOAf3uGp+YLILW3ysVOB2n/RE35r0hs3Thgrrvxke5HZ/g7YA U5uPTltd1t07CVDAUDE7thV18/gk3AbSphmsg+xTFSy8T9CGbmhEkMByXRSJD3kqRgM5hLhm F3SpL53djmnu291AOYaxYfLxp+AOOFh8lynQGiGCWqVSc6LjMF/yFTkPYs+IZ7168n7dZ7We eBpoHAGWYFkEM/lp5rNnUk1X5YRBxPGWs/x2yrRH7VLaK/3jwB+HasHnXdjHQdu8/Sbhjhpt XU2qTP4vtexSkAARBmrr9JH79JU5pz71dvn1c7MScM3VqYj6b0DfvbUIAAwEnzfAk81Nhjug 4csUpArxgPilLjCGPLBsx7d1gV52OwQKhTECRON8nzSbMIIEwzCCAqugAwIBAgIDAJxoMA0G CSqGSIb3DQEBBAUAMHkxEDAOBgNVBAoTB1Jvb3QgQ0ExHjAcBgNVBAsTFWh0dHA6Ly93d3cu Y2FjZXJ0Lm9yZzEiMCAGA1UEAxMZQ0EgQ2VydCBTaWduaW5nIEF1dGhvcml0eTEhMB8GCSqG SIb3DQEJARYSc3VwcG9ydEBjYWNlcnQub3JnMB4XDTA0MDcwOTEyMjEwMVoXDTA1MDcwOTEy MjEwMVowQTEZMBcGA1UEAxMQQ0FjZXJ0IFVzZXIgQ2VydDEkMCIGCSqGSIb3DQEJARYVYWRt aW5AdGhlbGlnaHQub3JnLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzbW5 Uvsb/JC1kwxpp7Pec9h5c5izCup7yYmysaVMHL4yc9LD8XVI1OmVMw6XUyqqTlYxRE7973mk +gA5Jpid482nhUTSCZ+TyR16txGRVQl9IIFwqubjBy9M4w0xRgbyUVWQyunVWxigo19PEc7l vOTIjYyFPKcFzNN039yZ9Nani6UkcsTbR3GJhpHituzZJC7obZouuwHEZl1juyERMjWDQ/R0 ohwoGMjuRizT88xLeO+LNypGRoD3CumjWT0Fj4K6PUKcyGx1110Tw3ODEAemX0fem28DschN NoVwWLSrNi1Ajg2coZgZr7nAyaiA+Wne+0nRu4EuNbd+Hfl3qQIDAQABo4GLMIGIMAwGA1Ud EwEB/wQCMAAwVgYJYIZIAYb4QgENBEkWR1RvIGdldCB5b3VyIG93biBjZXJ0aWZpY2F0ZSBm b3IgRlJFRSBoZWFkIG92ZXIgdG8gaHR0cDovL3d3dy5jYWNlcnQub3JnMCAGA1UdEQQZMBeB FWFkbWluQHRoZWxpZ2h0Lm9yZy51azANBgkqhkiG9w0BAQQFAAOCAgEArv+bRcPAARaIX+DY 42w95vSU0kJ1rpHnVvVj4RWqlKHwMYrNLiTtH+1ERlxoedatiYEJK2A19OTwVx2AmIvbX64X /SQFKhyPBlkbCP9aGzDTSzfHfqTlseYcOCsFWDqnp+DcrEfYQdLv1Q97Imj/w/M3Vvw/UeHl +wf4OnKoLBeyYbZzs5FQTjGnZXrlhwHqE9RJQP7mTWVtDLE3fJ3kTPedNS44hAuTJE4a6otN MI1t7SkBFKWu5o36H2EQy1tDHBc3aMLvocvc8tlQp8JNojqnIr9L+pYHzIsCF4qSAYbVELM4 B/e4an5gsgtbfKxU4Haf9ETfmvSGzdOGCuu/GR7kdn+DtgBTm49OW13W3TsJUMBQMTu2FXXz +CTcBtKmGayD7FMVLLxP0IZuaESQwHJdFIkPeSpGAzmEuGYXdKkvnd2Oae7b3UA5hrFh8vGn 4A44WHyXKdAaIYJapVJzouMwX/IVOQ9iz4hnvXryft1ntZ54GmgcAZZgWQQz+Wnms2dSTVfl hEHE8Zaz/HbKtEftUtor/ePAH4dqwedd2MdB27z9JuGOGm1dTapM/i+17FKQABEGauv0kfv0 lTmnPvV2+fVzsxJwzdWpiPpvQN+9tQgADASfN8CTzU2GO6DhyxSkCvGA+KUuMIY8sGzHt3WB XnY7BAqFMQJE43yfNJsxggOHMIIDgwIBATCBgDB5MRAwDgYDVQQKEwdSb290IENBMR4wHAYD VQQLExVodHRwOi8vd3d3LmNhY2VydC5vcmcxIjAgBgNVBAMTGUNBIENlcnQgU2lnbmluZyBB dXRob3JpdHkxITAfBgkqhkiG9w0BCQEWEnN1cHBvcnRAY2FjZXJ0Lm9yZwIDAJxoMAkGBSsO AwIaBQCgggHbMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTA0 MDcxNTEyMTEwNlowIwYJKoZIhvcNAQkEMRYEFBAWEiPiiCM1zhUHxCWSsnUiNqbRMFIGCSqG SIb3DQEJDzFFMEMwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGRBgkrBgEEAYI3EAQxgYMwgYAweTEQMA4GA1UE ChMHUm9vdCBDQTEeMBwGA1UECxMVaHR0cDovL3d3dy5jYWNlcnQub3JnMSIwIAYDVQQDExlD QSBDZXJ0IFNpZ25pbmcgQXV0aG9yaXR5MSEwHwYJKoZIhvcNAQkBFhJzdXBwb3J0QGNhY2Vy dC5vcmcCAwCcaDCBkwYLKoZIhvcNAQkQAgsxgYOggYAweTEQMA4GA1UEChMHUm9vdCBDQTEe MBwGA1UECxMVaHR0cDovL3d3dy5jYWNlcnQub3JnMSIwIAYDVQQDExlDQSBDZXJ0IFNpZ25p bmcgQXV0aG9yaXR5MSEwHwYJKoZIhvcNAQkBFhJzdXBwb3J0QGNhY2VydC5vcmcCAwCcaDAN BgkqhkiG9w0BAQEFAASCAQAM0nl76PY1FmgtRmcXgmzqHhBLyEd3naKxkp/PPGa1PcVvxekk NgeceBhwcPZaciJXg8wJTj/C5qgVQgHX+gJdMEIiQpNo0p5axscpBkpQ9XMifO20QxZNsBOp WH1ZWbUKC6iCnXRpJkes0ize0IexV5HZQxFdz45Ba+ompRQpRiLkk+FK+5do4IncALIuNaXe Ax9dO0mOqoW1CqFCV02I83szMyMY2fZOWZX+L0e4QoDs43x9V1f7miR4GAakqbBtzNLKcCU7 jp/isvXshd8A9Q+fvUFLvJWDrB+gfvubiDlZRzwimrdZnEXTZVVM3Xf6d6D1hY4VbwVWEexK 1PqpAAAAAAAA --------------ms040307090707090805030106--