[33199] in bugtraq
Re: Re[2]: Hijacking Apache 2 via mod_perl
daemon@ATHENA.MIT.EDU (Steve G)
Thu Jan 22 16:40:06 2004
Message-ID: <20040122175110.26816.qmail@web9604.mail.yahoo.com>
Date: Thu, 22 Jan 2004 09:51:10 -0800 (PST)
From: Steve G <linux_4ever@yahoo.com>
To: 3APA3A <3APA3A@SECURITY.NNOV.RU>, Ben Laurie <ben@algroup.co.uk>
Cc: Steve Grubb <linux_4ever@yahoo.com>, bugtraq@securityfocus.com,
httpd security <security@httpd.apache.org>
In-Reply-To: <60705914.20040122203700@SECURITY.NNOV.RU>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
>At least, it's possible to store descriptors table and
>implement check for descriptor in every perl file/socket
>function inside mod_perl (and mod_php and mod_something) and
>only allow access to std descriptors and to descriptors open
>inside same script. The choice is between speed and security.
Right. To me, that sounds ideal. In these days of 3 GHz machines,
I don't mind a little extra checking if it makes things more
secure.
-Steve Grubb
__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free web site building tool. Try it!
http://webhosting.yahoo.com/ps/sb/