httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Neelay Shah <asknee...@yahoo.com>
Subject Re: [users@httpd] Securing Apache configuration
Date Fri, 12 Aug 2005 02:22:23 GMT

Well, there are some programs like "junction"
available on sysinternals that supposedly make hard
link equivalent on windows...and the point is the user
can create a hard link to c:\ in his user dir. and it
will expose the whole hard drive and that is why I am
concerned about it...how to stop the web server from
following ...

Neelay


--- "Roger B.A. Klorese " <rogerk@queernet.org> wrote:

> Neelay Shah wrote:
> 
> >So, if one of the users in his home directory
> creates
> >a hard link to C:/ there is no way I could
> configure
> >the web server to avoid following that hard
> >link..following the link would display the contents
> of
> >the "C:/"
> >  
> >
> 
> 
> Hard links don't exist in Windows, do they?
> 
> And on Linux and other Unixen they require suitable
> permissions on the 
> object.
> 
>
---------------------------------------------------------------------
> The official User-To-User support forum of the
> Apache HTTP Server Project.
> See <URL:http://httpd.apache.org/userslist.html> for
> more info.
> To unsubscribe, e-mail:
> users-unsubscribe@httpd.apache.org
>    "   from the digest:
> users-digest-unsubscribe@httpd.apache.org
> For additional commands, e-mail:
> users-help@httpd.apache.org
> 
> 


__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message