Re: [Full-disclosure] Apache suEXEC privilege elevation / inform

看板Bugtraq作者時間12年前 (2013/08/12 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串10/32 (看更多)
Agreed. Many sites limit users to at most SymLinksIfOwnerMatch for that very reason, not to mention limits on CGI privileges. AllowSymlinks, IMO, ought to be reserved for the sysadmin on the server and used sparingly. You can, of course, even require .htaccess configurations to be set in the server's configuration files instead of in the user account areas (in conjunction with the AllowOverride None setting). --Tobias On 8/11/2013 7:52 AM, Michal Zalewski wrote: >> for doing this features in httpd.conf you can use AllowOverride None instead >> of AllowOverride all > AllowSymlinks is a red herring here (hardlinks should do, unless you > have stuff partitioned in a very thoughtful way, which most don't), > similarly to suexec. > > In general, sharing web hosting providers that allow shell access or > scripting are pretty much boned in a myriad of ways. > > /mz
文章代碼(AID): #1I1z5V49 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 10 之 32 篇):
文章代碼(AID): #1I1z5V49 (Bugtraq)