Loading docs/manual/misc/security_tips.html +6 −0 Changes for docs/manual/misc/security_tips.html: 6 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -170,7 +170,13 @@ Also be wary of playing games with the >UserDir</A> directive; setting it to something like <SAMP>"./"</SAMP> would have the same effect, for root, as the first example above. If you are using Apache 1.3 or above, we strongly recommend that you include the following line in your server configuration files: </P> <DL> <DD><SAMP>UserDir disabled root</SAMP> </DD> </DL> <HR> <P>Please send any other useful security tips to The Apache Group Loading docs/manual/mod/mod_userdir.html +39 −10 Changes for docs/manual/mod/mod_userdir.html: 39 added lines, 10 removed lines. Original line number Diff line number Diff line Loading @@ -33,13 +33,37 @@ is compiled in by default. It provides for user-specific directories. <strong>Status:</strong> Base<br> <strong>Module:</strong> mod_userdir<br> <strong>Compatibility:</strong> All forms except the <code>UserDir public_html</code> form are only available in Apache 1.1 or above.<p> public_html</code> form are only available in Apache 1.1 or above. Use of the <SAMP>enabled</SAMP> keyword, or <SAMP>disabled</SAMP> with a list of usernames, is only available in Apache 1.3 and above.<p> The UserDir directive sets the real directory in a user's home directory to use when a request for a document for a user is received. <em>Directory</em> is either <code>disabled</code>, to disable this feature, or the name of a directory, following one of the following patterns. If not disabled, then a request for <em>Directory/filename</em> is one of the following: </P> <UL> <LI>The name of a directory or a pattern such as those shown below. </LI> <LI>The keyword <SAMP>disabled</SAMP>. This turns off <EM>all</EM> username-to-directory translations except those explicitly named with the <SAMP>enabled</SAMP> keyword (see below). </LI> <LI>The keyword <SAMP>disabled</SAMP> followed by a space-delimited list of usernames. Usernames that appear in such a list will <EM>never</EM> have directory translation performed, even if they appear in an <SAMP>enabled</SAMP> clause. </LI> <LI>The keyword <SAMP>enabled</SAMP> followed by a space-delimited list of usernames. These usernames will have directory translation performed even if a global disable is in effect, but not if they also appear in a <SAMP>disabled</SAMP> clause. </LI> </UL> <P> If neither the <SAMP>enabled</SAMP> nor the <SAMP>disabled</SAMP> keywords appear in the <SAMP>Userdir</SAMP> directive, the argument is treated as a filename pattern, and is used to turn the name into a directory specification. A request for <code>http://www.foo.com/~bob/one/two.html</code> will be translated to: <pre> UserDir public_html -> ~bob/public_html/one/two.html Loading @@ -52,12 +76,17 @@ UserDir http://www.foo.com/users -> http//www.foo.com/users/bob/one/two.html UserDir http://www.foo.com/*/usr -> http://www.foo.com/bob/usr/one/two.html UserDir http://www.foo.com/~*/ -> http://www.foo.com/~bob/one/two.html </pre> <P> </P> <BLOCKQUOTE> <STRONG> Be careful when using this directive; for instance, <SAMP>"UserDir ./"</SAMP> would map <SAMP>"/~root"</SAMP> to <SAMP>"/"</SAMP> - which is probably undesirable. See also Be careful when using this directive; for instance, <SAMP>"UserDir ./"</SAMP> would map <SAMP>"/~root"</SAMP> to <SAMP>"/"</SAMP> - which is probably undesirable. If you are running Apache 1.3 or above, it is strongly recommended that your configuration include a "<SAMP>UserDir disabled root</SAMP>" declaration. See also the <A HREF="core.html#directory" Loading @@ -68,7 +97,7 @@ directive and the >Security Tips</A> page for more information. </STRONG> </P> </BLOCKQUOTE> <!--#include virtual="footer.html" --> </BODY> Loading Loading
docs/manual/misc/security_tips.html +6 −0 Changes for docs/manual/misc/security_tips.html: 6 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -170,7 +170,13 @@ Also be wary of playing games with the >UserDir</A> directive; setting it to something like <SAMP>"./"</SAMP> would have the same effect, for root, as the first example above. If you are using Apache 1.3 or above, we strongly recommend that you include the following line in your server configuration files: </P> <DL> <DD><SAMP>UserDir disabled root</SAMP> </DD> </DL> <HR> <P>Please send any other useful security tips to The Apache Group Loading
docs/manual/mod/mod_userdir.html +39 −10 Changes for docs/manual/mod/mod_userdir.html: 39 added lines, 10 removed lines. Original line number Diff line number Diff line Loading @@ -33,13 +33,37 @@ is compiled in by default. It provides for user-specific directories. <strong>Status:</strong> Base<br> <strong>Module:</strong> mod_userdir<br> <strong>Compatibility:</strong> All forms except the <code>UserDir public_html</code> form are only available in Apache 1.1 or above.<p> public_html</code> form are only available in Apache 1.1 or above. Use of the <SAMP>enabled</SAMP> keyword, or <SAMP>disabled</SAMP> with a list of usernames, is only available in Apache 1.3 and above.<p> The UserDir directive sets the real directory in a user's home directory to use when a request for a document for a user is received. <em>Directory</em> is either <code>disabled</code>, to disable this feature, or the name of a directory, following one of the following patterns. If not disabled, then a request for <em>Directory/filename</em> is one of the following: </P> <UL> <LI>The name of a directory or a pattern such as those shown below. </LI> <LI>The keyword <SAMP>disabled</SAMP>. This turns off <EM>all</EM> username-to-directory translations except those explicitly named with the <SAMP>enabled</SAMP> keyword (see below). </LI> <LI>The keyword <SAMP>disabled</SAMP> followed by a space-delimited list of usernames. Usernames that appear in such a list will <EM>never</EM> have directory translation performed, even if they appear in an <SAMP>enabled</SAMP> clause. </LI> <LI>The keyword <SAMP>enabled</SAMP> followed by a space-delimited list of usernames. These usernames will have directory translation performed even if a global disable is in effect, but not if they also appear in a <SAMP>disabled</SAMP> clause. </LI> </UL> <P> If neither the <SAMP>enabled</SAMP> nor the <SAMP>disabled</SAMP> keywords appear in the <SAMP>Userdir</SAMP> directive, the argument is treated as a filename pattern, and is used to turn the name into a directory specification. A request for <code>http://www.foo.com/~bob/one/two.html</code> will be translated to: <pre> UserDir public_html -> ~bob/public_html/one/two.html Loading @@ -52,12 +76,17 @@ UserDir http://www.foo.com/users -> http//www.foo.com/users/bob/one/two.html UserDir http://www.foo.com/*/usr -> http://www.foo.com/bob/usr/one/two.html UserDir http://www.foo.com/~*/ -> http://www.foo.com/~bob/one/two.html </pre> <P> </P> <BLOCKQUOTE> <STRONG> Be careful when using this directive; for instance, <SAMP>"UserDir ./"</SAMP> would map <SAMP>"/~root"</SAMP> to <SAMP>"/"</SAMP> - which is probably undesirable. See also Be careful when using this directive; for instance, <SAMP>"UserDir ./"</SAMP> would map <SAMP>"/~root"</SAMP> to <SAMP>"/"</SAMP> - which is probably undesirable. If you are running Apache 1.3 or above, it is strongly recommended that your configuration include a "<SAMP>UserDir disabled root</SAMP>" declaration. See also the <A HREF="core.html#directory" Loading @@ -68,7 +97,7 @@ directive and the >Security Tips</A> page for more information. </STRONG> </P> </BLOCKQUOTE> <!--#include virtual="footer.html" --> </BODY> Loading