Commit 63f2e1ed authored by Nilgun Belma Buguner's avatar Nilgun Belma Buguner
Browse files

update transformation

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@694601 13f79535-47bb-0310-9956-ffa450edef68
parent d77ecd6e
Loading
Loading
Loading
Loading
+30 −26
Changes for docs/manual/misc/security_tips.html.en: 30 added lines, 26 removed lines.
Original line number Diff line number Diff line
@@ -19,7 +19,8 @@
<a href="http://www.apache.org/">Apache</a> &gt; <a href="http://httpd.apache.org/">HTTP Server</a> &gt; <a href="http://httpd.apache.org/docs/">Documentation</a> &gt; <a href="../">Version 2.0</a> &gt; <a href="./">Miscellaneous Documentation</a></div><div id="page-content"><div id="preamble"><h1>Security Tips</h1>
<div class="toplang">
<p><span>Available Languages: </span><a href="../en/misc/security_tips.html" title="English">&nbsp;en&nbsp;</a> |
<a href="../ko/misc/security_tips.html" hreflang="ko" rel="alternate" title="Korean">&nbsp;ko&nbsp;</a></p>
<a href="../ko/misc/security_tips.html" hreflang="ko" rel="alternate" title="Korean">&nbsp;ko&nbsp;</a> |
<a href="../tr/misc/security_tips.html" hreflang="tr" rel="alternate" title="Trke">&nbsp;tr&nbsp;</a></p>
</div>

    <p>Some hints and tips on security issues in setting up a web server.
@@ -69,8 +70,8 @@
    protected from modification by non-root users. Not only must the files
    themselves be writeable only by root, but so must the directories, and
    parents of all directories. For example, if you choose to place
    ServerRoot in  /usr/local/apache then it is suggested that you create 
    that directory as root, with commands like these:</p>
    ServerRoot in  <code>/usr/local/apache</code> then it is suggested that
    you create that directory as root, with commands like these:</p>

    <div class="example"><p><code>
      mkdir /usr/local/apache <br />
@@ -81,9 +82,10 @@
      chmod 755 . bin conf logs
    </code></p></div>

    <p>It is assumed that /, /usr, and /usr/local are only modifiable by 
    root. When you install the <code class="program"><a href="../programs/httpd.html">httpd</a></code> executable, you
    should ensure that it is similarly protected:</p>
    <p>It is assumed that <code>/</code>, <code>/usr</code>, and
    <code>/usr/local</code> are only modifiable by root. When you install the
    <code class="program"><a href="../programs/httpd.html">httpd</a></code> executable, you should ensure that it is
    similarly protected:</p>

    <div class="example"><p><code>
      cp httpd /usr/local/apache/bin <br />
@@ -122,9 +124,10 @@
    significant.</p>

    <p>SSI files also pose the same risks that are associated with CGI
    scripts in general. Using the "exec cmd" element, SSI-enabled files 
    can execute any CGI script or program under the permissions of the 
    user and group Apache runs as, as configured in httpd.conf.</p>
    scripts in general. Using the <code>exec cmd</code> element, SSI-enabled
    files can execute any CGI script or program under the permissions of the
    user and group Apache runs as, as configured in
    <code>httpd.conf</code>.</p>

    <p>There are ways to enhance the security of SSI files while still
    taking advantage of the benefits they provide.</p>
@@ -133,17 +136,17 @@
    administrator can enable <a href="../suexec.html">suexec</a> as
    described in the <a href="#cgi">CGI in General</a> section.</p>

    <p>Enabling SSI for files with .html or .htm extensions can be 
    dangerous. This is especially true in a shared, or high traffic, 
    server environment. SSI-enabled files should have a separate extension,
    such as the conventional .shtml. This helps keep server load at a 
    minimum and allows for easier management of risk.</p>
    <p>Enabling SSI for files with <code>.html</code> or <code>.htm</code>
    extensions can be dangerous. This is especially true in a shared, or high
    traffic, server environment. SSI-enabled files should have a separate
    extension, such as the conventional <code>.shtml</code>. This helps keep
    server load at a minimum and allows for easier management of risk.</p>

    <p>Another solution is to disable the ability to run scripts and
    programs from SSI pages. To do this replace <code>Includes</code>
    with <code>IncludesNOEXEC</code> in the <code class="directive"><a href="../mod/core.html#options">Options</a></code> directive.  Note that users may
    still use &lt;--#include virtual="..." --&gt; to execute CGI scripts if 
    these scripts are in directories designated by a <code class="directive"><a href="../mod/mod_alias.html#scriptalias">ScriptAlias</a></code> directive.</p>
    still use <code>&lt;--#include virtual="..." --&gt;</code> to execute CGI
    scripts if these scripts are in directories designated by a <code class="directive"><a href="../mod/mod_alias.html#scriptalias">ScriptAlias</a></code> directive.</p>

  </div><div class="top"><a href="#page-header"><img alt="top" src="../images/up.gif" /></a></div>
<div class="section">
@@ -205,13 +208,13 @@

    

  <p>
  Embedded scripting options which run as part of the server itself,
  such as mod_php, mod_perl, mod_tcl, and mod_python, run under the
  identity of the server itself (see the <code class="directive"><a href="../mod/mpm_common.html#user">User</a></code> directive), and therefore
  scripts executed by these engines potentially can access anything the
  server user can. Some scripting engines may provide restrictions, but
  it is better to be safe and assume not.</p>
    <p>Embedded scripting options which run as part of the server itself,
    such as <code>mod_php</code>, <code>mod_perl</code>, <code>mod_tcl</code>,
    and <code>mod_python</code>, run under the identity of the server itself
    (see the <code class="directive"><a href="../mod/mpm_common.html#user">User</a></code> directive), and
    therefore scripts executed by these engines potentially can access
    anything the server user can. Some scripting engines may provide
    restrictions, but it is better to be safe and assume not.</p>

  </div><div class="top"><a href="#page-header"><img alt="top" src="../images/up.gif" /></a></div>
<div class="section">
@@ -283,8 +286,8 @@
    &lt;Location /&gt;</code> directive might overturn it.</p>

    <p>Also be wary of playing games with the <code class="directive"><a href="../mod/mod_userdir.html#userdir">UserDir</a></code> directive; setting it to
    something like "./" would have the same effect, for root, as the first 
    example above. If you are using Apache 1.3 or above, we strongly 
    something like <code>./</code> would have the same effect, for root, as
    the first example above. If you are using Apache 1.3 or above, we strongly
    recommend that you include the following line in your server
    configuration files:</p>

@@ -343,7 +346,8 @@
  </div></div>
<div class="bottomlang">
<p><span>Available Languages: </span><a href="../en/misc/security_tips.html" title="English">&nbsp;en&nbsp;</a> |
<a href="../ko/misc/security_tips.html" hreflang="ko" rel="alternate" title="Korean">&nbsp;ko&nbsp;</a></p>
<a href="../ko/misc/security_tips.html" hreflang="ko" rel="alternate" title="Korean">&nbsp;ko&nbsp;</a> |
<a href="../tr/misc/security_tips.html" hreflang="tr" rel="alternate" title="Trke">&nbsp;tr&nbsp;</a></p>
</div><div id="footer">
<p class="apache">Copyright 2008 The Apache Software Foundation.<br />Licensed under the <a href="http://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.</p>
<p class="menu"><a href="../mod/">Modules</a> | <a href="../mod/directives.html">Directives</a> | <a href="../faq/">FAQ</a> | <a href="../glossary.html">Glossary</a> | <a href="../sitemap.html">Sitemap</a></p></div>
+4 −2
Changes for docs/manual/misc/security_tips.html.ko.euc-kr: 4 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -19,7 +19,8 @@
<a href="http://www.apache.org/">Apache</a> &gt; <a href="http://httpd.apache.org/">HTTP Server</a> &gt; <a href="http://httpd.apache.org/docs/">Documentation</a> &gt; <a href="../">Version 2.0</a> &gt; <a href="./">Miscellaneous Documentation</a></div><div id="page-content"><div id="preamble"><h1>보안 팁</h1>
<div class="toplang">
<p><span>가능한 언어: </span><a href="../en/misc/security_tips.html" hreflang="en" rel="alternate" title="English">&nbsp;en&nbsp;</a> |
<a href="../ko/misc/security_tips.html" title="Korean">&nbsp;ko&nbsp;</a></p>
<a href="../ko/misc/security_tips.html" title="Korean">&nbsp;ko&nbsp;</a> |
<a href="../tr/misc/security_tips.html" hreflang="tr" rel="alternate" title="T&#252;rk&#231;e">&nbsp;tr&nbsp;</a></p>
</div>
<div class="outofdate">이 문서는 최신판 번역이 아닙니다.
            최근에 변경된 내용은 영어 문서를 참고하세요.</div>
@@ -336,7 +337,8 @@
  </div></div>
<div class="bottomlang">
<p><span>가능한 언어: </span><a href="../en/misc/security_tips.html" hreflang="en" rel="alternate" title="English">&nbsp;en&nbsp;</a> |
<a href="../ko/misc/security_tips.html" title="Korean">&nbsp;ko&nbsp;</a></p>
<a href="../ko/misc/security_tips.html" title="Korean">&nbsp;ko&nbsp;</a> |
<a href="../tr/misc/security_tips.html" hreflang="tr" rel="alternate" title="T&#252;rk&#231;e">&nbsp;tr&nbsp;</a></p>
</div><div id="footer">
<p class="apache">Copyright 2008 The Apache Software Foundation.<br />Licensed under the <a href="http://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.</p>
<p class="menu"><a href="../mod/">모듈</a> | <a href="../mod/directives.html">지시어들</a> | <a href="../faq/">FAQ</a> | <a href="../glossary.html">용어</a> | <a href="../sitemap.html">사이트맵</a></p></div>
+2 −2
Changes for docs/manual/mod/mpm_common.html.en: 2 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -363,8 +363,8 @@ listens to</td></tr>
<div class="top"><a href="#page-header"><img alt="top" src="../images/up.gif" /></a></div>
<div class="directive-section"><h2><a name="MaxClients" id="MaxClients">MaxClients</a> <a name="maxclients" id="maxclients">Directive</a></h2>
<table class="directive">
<tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Maximum number of child processes that will be created
to serve requests</td></tr>
<tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Maximum number of simultaneous requests that will
be served</td></tr>
<tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code>MaxClients <var>number</var></code></td></tr>
<tr><th><a href="directive-dict.html#Default">Default:</a></th><td><code>See usage for details</code></td></tr>
<tr><th><a href="directive-dict.html#Context">Context:</a></th><td>server config</td></tr>
+1 −2
Changes for docs/manual/mod/mpm_common.html.tr.utf8: 1 added line, 2 removed lines.
Original line number Diff line number Diff line
@@ -368,8 +368,7 @@
<div class="top"><a href="#page-header"><img alt="top" src="../images/up.gif" /></a></div>
<div class="directive-section"><h2><a name="MaxClients" id="MaxClients">MaxClients</a> <a name="maxclients" id="maxclients">Yönergesi</a></h2>
<table class="directive">
<tr><th><a href="directive-dict.html#Description">Açıklama:</a></th><td>İstekleri sunarken oluşturulacak çocuk süreçlerin azami sayısını
  belirler.</td></tr>
<tr><th><a href="directive-dict.html#Description">Açıklama:</a></th><td>Aynı anda sunulacak azami istek sayısı</td></tr>
<tr><th><a href="directive-dict.html#Syntax">Sözdizimi:</a></th><td><code>MaxClients <var>sayı</var></code></td></tr>
<tr><th><a href="directive-dict.html#Default">Öntanımlı:</a></th><td><code>Ayrıntılar için aşağıdaki açıklamaya bakınız.</code></td></tr>
<tr><th><a href="directive-dict.html#Context">Bağlam:</a></th><td>sunucu geneli</td></tr>
+1 −1
Changes for docs/manual/mod/mpm_common.xml.de: 1 added line, 1 removed line.
Original line number Diff line number Diff line
<?xml version="1.0"?>
<!DOCTYPE modulesynopsis SYSTEM "../style/modulesynopsis.dtd">
<?xml-stylesheet type="text/xsl" href="../style/manual.de.xsl"?>
<!-- English Revision: 421174:658428 (outdated) -->
<!-- English Revision: 421174:692460 (outdated) -->

<!--
 Licensed to the Apache Software Foundation (ASF) under one or more
Loading