Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 18 Oct 2001 15:39:54 +0400
From:      "Andrey A. Chernov" <ache@nagual.pp.ru>
To:        Sheldon Hearn <sheldonh@starjuice.net>
Cc:        ports@freebsd.org, arch@freebsd.org
Subject:   Re: HEADS UP: Apache port change from nobody:nogroup to www:www planned
Message-ID:  <20011018153954.B63215@nagual.pp.ru>
In-Reply-To: <27516.1003402941@axl.seasidesoftware.co.za>
References:  <20011018145428.B62250@nagual.pp.ru> <27516.1003402941@axl.seasidesoftware.co.za>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, Oct 18, 2001 at 13:02:21 +0200, Sheldon Hearn wrote:
> 
> It just seems weird to me that you haven't just left this area up to
> things like the Apache SuExec project etc.  CGI scripts are complex
> beasts, and I wonder how much real security you gain with this
> simplistic "solution".

I don't attempt to deal with this area or attempt to solve it this way. I
issue just _warning_ saying that webmasters which use non-wrapped cgi-bin
writes shoud convert their directories to group www after Apache change.

-- 
Andrey A. Chernov
http://ache.pp.ru/

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ports" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011018153954.B63215>