<p>Some hints and tips on security issues in setting up a web server.
@@ -146,8 +147,8 @@
protected from modification by non-root users. Not only must the files
themselves be writeable only by root, but so must the directories, and
parents of all directories. For example, if you choose to place
ServerRoot in /usr/local/apache then it is suggested that you create
that directory as root, with commands like these:</p>
ServerRoot in <code>/usr/local/apache</code> then it is suggested that
you create that directory as root, with commands like these:</p>
<divclass="example"><p><code>
mkdir /usr/local/apache <br/>
@@ -158,9 +159,10 @@
chmod 755 . bin conf logs
</code></p></div>
<p>It is assumed that /, /usr, and /usr/local are only modifiable by
root. When you install the <codeclass="program"><ahref="../programs/httpd.html">httpd</a></code> executable, you
should ensure that it is similarly protected:</p>
<p>It is assumed that <code>/</code>, <code>/usr</code>, and
<code>/usr/local</code> are only modifiable by root. When you install the
<codeclass="program"><ahref="../programs/httpd.html">httpd</a></code> executable, you should ensure that it is
similarly protected:</p>
<divclass="example"><p><code>
cp httpd /usr/local/apache/bin <br/>
@@ -199,9 +201,10 @@
significant.</p>
<p>SSI files also pose the same risks that are associated with CGI
scripts in general. Using the "exec cmd" element, SSI-enabled files
can execute any CGI script or program under the permissions of the
user and group Apache runs as, as configured in httpd.conf.</p>
scripts in general. Using the <code>exec cmd</code> element, SSI-enabled
files can execute any CGI script or program under the permissions of the
user and group Apache runs as, as configured in
<code>httpd.conf</code>.</p>
<p>There are ways to enhance the security of SSI files while still
taking advantage of the benefits they provide.</p>
@@ -210,17 +213,17 @@
administrator can enable <ahref="../suexec.html">suexec</a> as
described in the <ahref="#cgi">CGI in General</a> section.</p>
<p>Enabling SSI for files with .html or .htm extensions can be
dangerous. This is especially true in a shared, or high traffic,
server environment. SSI-enabled files should have a separate extension,
such as the conventional .shtml. This helps keep server load at a
minimum and allows for easier management of risk.</p>
<p>Enabling SSI for files with <code>.html</code> or <code>.htm</code>
extensions can be dangerous. This is especially true in a shared, or high
traffic, server environment. SSI-enabled files should have a separate
extension, such as the conventional <code>.shtml</code>. This helps keep
server load at a minimum and allows for easier management of risk.</p>
<p>Another solution is to disable the ability to run scripts and
programs from SSI pages. To do this replace <code>Includes</code>
with <code>IncludesNOEXEC</code> in the <codeclass="directive"><ahref="../mod/core.html#options">Options</a></code> directive. Note that users may
still use <--#include virtual="..." --> to execute CGI scripts if
these scripts are in directories designated by a <codeclass="directive"><ahref="../mod/mod_alias.html#scriptalias">ScriptAlias</a></code> directive.</p>
still use <code><--#include virtual="..." --></code> to execute CGI
scripts if these scripts are in directories designated by a <codeclass="directive"><ahref="../mod/mod_alias.html#scriptalias">ScriptAlias</a></code> directive.</p>
<pclass="apache">Copyright 2008 The Apache Software Foundation.<br/>Licensed under the <ahref="http://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.</p>
<pclass="apache">Copyright 2008 The Apache Software Foundation.<br/>Licensed under the <ahref="http://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.</p>
<tr><th><ahref="directive-dict.html#Default">Default:</a></th><td><code>Value of <codeclass="directive"><ahref="../mod/core.html#timeout">Timeout</a></code></code></td></tr>