Post by Rocket RayOptions +ExecCGI AddHandler cgi-script cgi
Well, I made a file called .htaccess with those lines, put it in both my
home directory and public-web directory, and it still doesn't work. Do I
need other stuff in that file?
Here is part of a response from a PrismNet admin. I don't know if this will
help.
It also seems that some applications might have moved from /usr/bin to
/usr/local/bin or vice versa.
================================================================
Jim,
We have made several changes with regard to home page security.
IO's original www administrators allowed cgi access to any directory
in the www and home tree. When we overhauled the www server this
weekend we changed the default behaviour of the server to only allow
cgi scripting in the ~/public-web/cgi-bin tree by default. We also
will now only parse included files as .shtml.
However we did allow individual users who wanted this ability to
change their own .htaccess file to add these options to their website.
This change was necessary because of the number of successful hacking
attempts via the web server. If any specific user had a comprimisable
cgi-script which would allow someone to "write" files to any directory
on the server they could then run those files. We were seeing scripts
showing up in /tmp, /var/tmp, all throughout the home tree as well as
other location.
With this new setup the only location where this type of behaviour is
active is in the cgi-bin directory unless the individual user opens up
their entire www tree to this type of hack.
Our default options for user home pages are now
Includes
MultiViews
Indexes
SymLinksIfOwnerMatch
IncludesNoExec
================================================================
Jim
--
Jim Menard, ***@io.com, http://www.io.com/~jimm/
"What's a Superbowl? Does it save the city from ruin and destruction ON TOP
OF containing some part of a complete breakfast?" -- J. on alt.fan.tom-servo