Skip to main content

question on the symlinks vunerability

Comments

2 comments

  • cPanelMichael
    Hello :) This is addressed on the following thread: Solutions for handling symlink attacks I've linked to the post where a list of solutions is available. Please direct any questions on the topic to that particular thread. Thank you.
    0
  • quizknows
    Definitely reference that other thread. However, what you WANT is symlinksifownermatch. Normal +followsymlinks is the issue; people can use apache to read other peoples config files without additional security precautions. Even if you disable +followsymlinks, normally users could just re-enable it in their own .htaccess, and many CMSes rely on that being on. If you use SuPHP, the "symlink race condition protection" in EasyApache is good enough IMO.
    0

Please sign in to leave a comment.