apache - Security problems regarding +FollowSymLinks and -SymLinksIfOwnerMatch? -


I am using it for one of my applications:

  option + follow-up Script - Simlinks IFOwnerMatch   

And I worry about security issues that can bring it. With any thought, what measures can I take to make this approach as safe as possible?

Let's use those options as safe as possible. The risk in using them is that a process running under a user or user can create a simulation or disclose information or abduct the material. For example, if a non-abusive user (who has been compromised) wants to read a file that they can not normally do, they can increase it by making a symlink from its public_HML directory, and if Apache can read it, then they can only access their webpage and read the file.

Note that this hazard is not just from users on your system. If you are running a webpage, then called php, and it has compromised somehow, an attacker is a PHP file browser And your document can create simulations for content outside of the root (like / etc / passwd or like any other file)

If you are worried about such things, then Use these options Htr not.

Comments

Popular posts from this blog

Python SQLAlchemy:AttributeError: Neither 'Column' object nor 'Comparator' object has an attribute 'schema' -

java - How not to audit a join table and related entities using Hibernate Envers? -

mongodb - CakePHP paginator ignoring order, but only for certain values -