Protection for sensitive files when using Apache on an HFS+ volume

Posted on March 6, 2008. Filed under: Apache, Hosting, Leopard, OSX, Servers | Tags: , , , |

Security Update 2004-12-02 makes changes to the httpd.conf file. After a successful update, the Apache configuration file will deny access to the following files:

  • */..namedfork/data
  • */..namedfork/rsrc
  • */rsrc
  • rsrc
  • .ht* (case insensitive)
  • .ds_s* (case insensitive)

Warnings:

  1. The configuration changes that block named-fork exposure apply only to the default webserver, apache1. If you’ve chosen to use Apache2, it’s recommended that you serve content from a UFS volume.
  2. For important related information, see “mod_hfs_apple” protects web content against case insensitivity in the HFS file system. (more…)

Read Full Post | Make a Comment ( None so far )

Recently on Mac OSX Hosting!...

Apple’s XSAN 2 with OSX Leopard

Posted on February 22, 2008. Filed under: Leopard, OSX, Software | Tags: , , , , , , |

Basic Command Line Utilities, Tips, & Commands

Posted on February 20, 2008. Filed under: Hosting, Leopard, OSX, Servers, Software | Tags: , , , , , , , |

Integrating OSX Clients with an OpenLDAP Directory

Posted on February 19, 2008. Filed under: Hosting, OSX, Servers, Xserve | Tags: , , , , , |

Review of FreeNAS

Posted on February 18, 2008. Filed under: Hosting, Servers, Software | Tags: , , , , , |

Need for a personal server? iServe?

Posted on February 18, 2008. Filed under: Apache, Leopard, OSX, Servers, Software | Tags: , , , , |

Installing WordPress on Mac OS X Tiger

Posted on February 18, 2008. Filed under: Content Management, OSX, Software, Web Development | Tags: , , , , , , , , |

Installing Movable Type on Tiger

Posted on February 13, 2008. Filed under: Apache, Hosting, Leopard, OSX, Servers, Software, Web Development | Tags: , , , , , , , , |

Leopard Server: Using ACLs with Open Directory

Posted on February 7, 2008. Filed under: Leopard, OSX, Servers, Software, Web Development | Tags: , , , |

Apple Remote Desktop Directory-based Authentication

Posted on February 7, 2008. Filed under: Leopard, OSX, Servers, Software | Tags: , , , , , , |

W3C HTML Validator on OS X

Posted on January 30, 2008. Filed under: Leopard, OSX, Software, Web Development | Tags: , , , , , |

  • Blog Stats

    • 40,581 hits
  • Email Subscription

    Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Liked it here?
Why not try sites on the blogroll...