Re: [Full-disclosure] Apache suEXEC privilege elevation / inform

看板Bugtraq作者時間12年前 (2013/08/12 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串10/32 (看更多)
> for doing this features in httpd.conf you can use AllowOverride None instead > of AllowOverride all AllowSymlinks is a red herring here (hardlinks should do, unless you have stuff partitioned in a very thoughtful way, which most don't), similarly to suexec. In general, sharing web hosting providers that allow shell access or scripting are pretty much boned in a myriad of ways. /mz
文章代碼(AID): #1I1z5VeH (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 10 之 32 篇):
文章代碼(AID): #1I1z5VeH (Bugtraq)