Go Back   cPanel Forums > cPanel® and WHM® (for Linux® and FreeBSD® Servers) > cPanel and WHM Discussions

View Poll Results: AllowOverride risk factor
Risk factor high, allows .htaccess over ride 3 42.86%
Risk factor low , doesnt seem to matter to much to most hosters 2 28.57%
Risk factor none ; no problem with that at all 2 28.57%
Risk ? Who cares 0 0%
Voters: 7. You may not vote on this poll

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-21-2006, 03:00 AM
gorilla's Avatar
Registered User
 
Join Date: Feb 2004
Location: Sydney / Australia
Posts: 731
gorilla is on a distinguished road
AllowOverride Risk Factor

Whats the general consent regarding AllowOverride ?
As one of the scripter from fantastico tryes to tell me that "AllowOverride ALL" in httpd.conf is not a security risk .
__________________
Regards
WiredGorilla
Australian Dedicated Servers | Web Hosting | WiredGorilla.com

Last edited by gorilla; 03-21-2006 at 03:05 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 03-21-2006, 09:40 AM
gorilla's Avatar
Registered User
 
Join Date: Feb 2004
Location: Sydney / Australia
Posts: 731
gorilla is on a distinguished road
or am i just beeing simply paranoid ?
__________________
Regards
WiredGorilla
Australian Dedicated Servers | Web Hosting | WiredGorilla.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-22-2006, 11:30 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
It's a security risk if it allows end-users to do things you don't want them to as part of your security model. Best practice is to allow only what you want to happen, rather than leaving the door open and inviting burgulars in. There's some interesting thoughts about AllowOverride here:
http://www.onlamp.com/pub/a/apache/2...pacheckbk.html
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 10:29 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc