Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 27 Aug 1997 23:04:49 -0400 (EDT)
From:      spork <spork@super-g.com>
To:        Don Wilde <don@PartsNow.com>
Cc:        questions@FreeBSD.ORG
Subject:   Re: Server Side Includes
Message-ID:  <Pine.BSF.3.96.970827230301.22473A-100000@super-g.inch.com>
In-Reply-To: <340489D3.76DC@PartsNow.com>

next in thread | previous in thread | raw e-mail | index | archive | help
You should be careful where you put SSI...

Especially if you have any pages (such as a guestbook) that allow users to
"create" html on the fly.  It's rather simple for someone to include an
SSI directive in their bulletin board post.  That command could do all
sorts of nasty things, such as rm -rf /, /usr/X11R6/bin/xterm, etc...

Charles

On Wed, 27 Aug 1997, Don Wilde wrote:

> In your srm.conf file, look for the line that says 'AddType
> text/x-server-parsed-html .shtml' I believe if you add .html to the end
> of it and kill -HUP the main httpd process, it will parse all pages at
> some cost in speed. 
> 
> If all you want to do is to put a counter on your homepage or something
> like that, change the DirectoryIndex to reference 'home.shtml' instead
> of 'index.shtml'. Of course, then you might need to rename all of your
> homepages :) Minor details... life as a webmaster... Next you'll be
> asking me about file locking in Perl for extranets. 8-0
> 
> -- 
>   oooOOO O O O o * * *  *   *   *
>  o     ___       _________ _________ ________ _________ _________ ___==_
>  V_=_=_DW ===--- Don Wilde [don@PartsNow.com] [http://www.PartsNow.com ]
> /oo0000oo-oo--oo-ooo---ooo-ooo---ooo-ooo--ooo-ooo---ooo-ooo---ooo-oo--oo
> 




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.96.970827230301.22473A-100000>