|
|||||||||||
|
Re: Apache 2.x leaked descriptors
From: Brian Hatch <vuln-dev(at)ifokr.org>
Date: Tue Feb 25 2003 - 12:27:43 EST > Apache 2.0 currently execs cgi scripts / server side includes etc... with
I don't see any reason for the access log to be writeable, however, so I agree they should all be closed. If the error log (the only one that is appropriate for the exec'd program in question) is opened in append only mode, this seems to be appropriate. I think an apache directive to allow all logs to be closed would be a good one, or perhaps a flag to define close on exec when you define your log files. -- Brian Hatch So many pedestrians, Systems and so little time. Security Engineer http://www.ifokr.org/bri/ Every message PGP signed
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT |
||||||||||
|
|||||||||||