Small security hole in apache configuration
| From: | Damien Bobillot | Date: | Thu, 09 Sep 2004 20:30:31 +0000 |
| Subject: | Small security hole in apache configuration | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-26156@lists.php.net to get a copy of this message | ||
Hello,
While searching "apache site:www.php.net" in google, I've seen that the mod_status plugin of apache is loaded and configured without any restriction. It may be accessed by everybody at the page :
http://www.php.net/server-status
You should reduce access to this access to very few IP adresses or password protect this page.
--
Damien Bobillot