Re: apache manual language

Rui Miguel Silva Seabra <[email protected]>
Newsgroups gmane.linux.redhat.release.limbo
Message-ID <1032265963.27419.36.camel@roque>
On Tue, 2002-09-17 at 11:12, Joe Orton wrote:
> On Mon, Sep 16, 2002 at 03:28:00PM +0100, Rui Miguel Silva Seabra wrote:
> > I think that this is pretty darn obvious but if you have:
> > 
> >   * FollowSymLinks
> >     you immediately have ln -s /sentive/file fileOnTheWeb
> >   * Indexes
> >     potential directory disclosures
> >   * MultiViews
> >     potential bugs due to more complex code
> 
> MultiViews is only enabled by default for the the manual directory;  
> disabling FollowSymLinks is a performance hit; maybe Indexes should be
> indeed be off by default, could you file a bugzilla bug on that?

Disabling FollowSymLinks is a performance improvement, not hit.

> > The default should have Options None
> > 
> > While we're at it, you should use:
> > ServerSignature Off      # currently you leave it on
> > ServerTokens Prod        # currently not even used
> > 
> > While, usually, minor issues, the default configuration gives away too
> > much information, easing up the lives of script kiddies all around :)
> 
> The default as of the beta releases is currently "ServerTokens OS" which
> makes the default Server header "Apache/2.0.x (Red Hat Linux)".

Well, I can see the need for branding in there, but I still stand for
that it is better to have just Prod, resulting in "Server: Apache"

Bug registered as:
   https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=74174

Rui

-- 
+ No matter how much you do, you never do enough -- unknown
+ Whatever you do will be insignificant,
| but it is very important that you do it -- Gandhi
+ So let's do it...?
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQA9hyDqo+C50no0+t4RAjlcAKCZ1scB14+DPv1DIHqY5eHKfwv0PACfUenN
kFzPJt+huDfl4aSrH8teUjY=
=Ixk4
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.