1. 18 Oct, 2000 1 commit
    • Tony Finch's avatar
      Tighten up the syntax checking of Host: headers to fix a · 7b2aa25b
      Tony Finch authored
      security bug in some mass virtual hosting configurations
      that can allow a remote attacker to retrieve some files
      on the system that should be inaccessible. The problem
      occured with requests including the line "Host: ..." --
      the last dot is stripped and the remaining ".." then
      reveals a parent directory.
      
      Reported by: Peter Christoffersen <pch@mindpass.com>
      Message-ID: <8quts6$2el$1@news.inet.tele.dk>
      Newsgroups: comp.infosystems.www.servers.unix
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@86637 13f79535-47bb-0310-9956-ffa450edef68
      7b2aa25b
  2. 17 Oct, 2000 14 commits
  3. 16 Oct, 2000 13 commits
  4. 15 Oct, 2000 8 commits
  5. 14 Oct, 2000 4 commits