Re: apache AllowOverride and .htaccess

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Friday, September 14, 2007 - 8:29 pm

On Fri, Sep 14, 2007 at 07:10:22PM -0500, Jacob Yocom-Piatt wrote:

"AllowOverride All" means that if someone manages to put .htaccess
anywhere lower tree then they can override things you didn't intend,
etc. It's not especially nice. Don't think "show me an exploit," think
attack mitigation.

Do you *really* need to do this in .htaccess? Anything you can
accomplish there can also be done in in the config, no?

--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
apache AllowOverride and .htaccess, Jacob Yocom-Piatt, (Fri Sep 14, 8:10 pm)
Re: apache AllowOverride and .htaccess, Celso Fernandes, (Fri Sep 14, 9:22 pm)
Re: apache AllowOverride and .htaccess, Darrin Chandler, (Fri Sep 14, 8:29 pm)