Re: Small security hole in apache configuration
| From: | Edin Kadribasic | Date: | Fri, 10 Sep 2004 11:39:52 +0000 |
| Subject: | Re: Small security hole in apache configuration | ||
| References: | 1 | Groups: | php.mirrors |
| Request: | Send a blank email to php-mirrors+get-26162@lists.php.net to get a copy of this message | ||
Hi,
mod_status is enabled on purpose. No security hole there.
Edin
----- Original Message -----
From: "Damien Bobillot" <damien.bobillot@m4x.org>
To: <webmaster@php.net>
Sent: Thursday, September 09, 2004 10:30 PM
Subject: Small security hole in apache configuration
Hello,
While searching "apache site:www.php.net" in google, I've seen that the
mod_status plugin of apache is loaded and configured without any
restriction. It may be accessed by everybody at the page :
http://www.php.net/server-status
You should reduce access to this access to very few IP adresses or
password protect this page.
--
Damien Bobillot