Re: PHP Security Alert for Apache/Win32
| From: | (David) | Date: | Sun, 06 Jan 2002 13:58:00 +0000 |
| Subject: | Re: PHP Security Alert for Apache/Win32 | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-79606@lists.php.net to get a copy of this message | ||
Wow!, i tried it and it really works, this is serious man! is there a fix around it without safe
mode like GED suggested?
>Folks running Apache/Win32 should read this:
>
>http://www.securiteam.com/windowsntfocus/5ZP030U60U.html
>
>If you run in CGI mode you likely have a line similar to >the
>following in your httpd.conf:
>ScriptAlias /php/ \"C:php\"
>
>Also, if you run SAPI mode (apache plugin mode) and used
>to run CGI, make sure that that line is commented out.
>
>Has someone else got an idea for a workaround, without >having
>to go into safe-mode? Would safe-mode be able to prevent >this?
>
>-GED
>
>Northern.CA ===--
>http://www.northern.ca
>Canada\'s Search Engine
>