Archive for March, 2008
Protection for sensitive files when using Apache on an HFS+ volume
We are moving this blog to a new server.
Security Update 2004-12-02 makes changes to the httpd.conf file. After a successful update, the Apache configuration file will deny access to the following files:
*/..namedfork/data
*/..namedfork/rsrc
*/rsrc
rsrc
.ht* (case insensitive)
.ds_s* (case insensitive)
Warnings:
The configuration changes that block named-fork exposure apply only to the default webserver, apache1. If you’ve chosen to use Apache2, [...]
Read Full Post | Make a Comment ( None so far )
RSS - Posts