httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Boyle Owen" <Owen.Bo...@swx.com>
Subject RE: [users@httpd] RE: htaccess AuthType Basic: some files get served without a password challenge!
Date Wed, 01 Feb 2006 12:09:57 GMT
 

> -----Original Message-----
> From: news [mailto:news@sea.gmane.org] On Behalf Of Peter
> 
> You may email me privately, and I will provide a true URL. Thx

shoot...

> 
> > Rgds,
> > Owen Boyle
> > Disclaimer: Any disclaimer attached to this message may be ignored.
> > 
> >> Same with
> >> http://mysecure.dir/file.ico
> >> of even a file with no extension
> >> http://mysecure.dir/file
> >> and
> >> http://mysecure.dir/file.zip
> >> will also be served without a challenge. But
> >> http://mysecure.dir/file.gif
> >> always is challenged as well as
> >> http://mysecure.dir/file.html
> >> 
> >> Of course, if the files don't exist mostly I get a 404 
> error instead of
> >> a
> >> password challenge and sometimes just a blank screen.
> >> 
> >> My question is WHY? My hosting company uses Apache 1.3.31 and of
> >> course, they're of little help.
> >> 
> >> I tried playing with the Limit and file directives, but 
> they seem not
> >> to work. I have two questions:
> >> 1) I searched the bugs and found some similar issues. Is 
> this behavior
> >> normal? Or, am I doing something wrong? 2) Is there a way 
> I can protect
> >> this dir from direct file access, or do I need to rename 
> everything to
> >> .gif in order to protect it?
> >> 
> >> Thanks in advance.
> >> 
> >> 
> >> 
> ---------------------------------------------------------------------
> >> The official User-To-User support forum of the Apache HTTP Server
> >> Project.
> >> See <URL:http://httpd.apache.org/userslist.html> for more info. To
> >> unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
> >>    "   from the digest: users-digest-unsubscribe@httpd.apache.org
> >> For additional commands, e-mail: users-help@httpd.apache.org
> >> 
> >> 
> > Diese E-mail ist eine private und persönliche Kommunikation. Sie hat
> > keinen Bezug zur Börsen- bzw. Geschäftstätigkeit der SWX 
> Gruppe. This
> > e-mail is of a private and personal nature. It is not related to the
> > exchange or business activities of the SWX Group. Le 
> présent e-mail est
> > un message privé et personnel, sans rapport avec l'activité 
> boursière
> > du Groupe SWX.
> >  
> >  
> > This message is for the named person's use only. It may contain
> > confidential, proprietary or legally privileged information. No
> > confidentiality or privilege is waived or lost by any 
> mistransmission.
> > If you receive this message in error, please notify the 
> sender urgently
> > and then immediately delete the message and any copies of 
> it from your
> > system. Please also immediately destroy any hardcopies of 
> the message.
> > You must not, directly or indirectly, use, disclose, 
> distribute, print,
> > or copy any part of this message if you are not the 
> intended recipient.
> > The sender's company reserves the right to monitor all e-mail
> > communications through their networks. Any views expressed in this
> > message are those of the individual sender, except where the message
> > states otherwise and the sender is authorised to state them 
> to be the
> > views of the sender's company.
> > 
> > 
> ---------------------------------------------------------------------
> > The official User-To-User support forum of the Apache HTTP Server
> > Project. See <URL:http://httpd.apache.org/userslist.html> 
> for more info.
> > To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
> >    "   from the digest: users-digest-unsubscribe@httpd.apache.org
> > For additional commands, e-mail: users-help@httpd.apache.org
> 
> 
> 
> ---------------------------------------------------------------------
> The official User-To-User support forum of the Apache HTTP 
> Server Project.
> See <URL:http://httpd.apache.org/userslist.html> for more info.
> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
>    "   from the digest: users-digest-unsubscribe@httpd.apache.org
> For additional commands, e-mail: users-help@httpd.apache.org
> 
> 

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message