Sergio Cuéllar Valdés dijo [Thu, Mar 27, 2008 at 04:00:00PM -0600]: > Hi Gunnar, > > I think it should be moved to /usr/bin, for the reason you have > exposed. But if the -p is not implemented yet, the default port is > still 80 in the example you gave. But you cannot bind that port as > normal user ? Can you ?
No, you cannot yet bind. But I believe in Álvaro's word - Trust him, he will fix this ;-) I'm just plaing a bit with the security implications... Say, Joe Random User gets a shell account in your shared host, and just to test it, runs «cherokee -r / -p 1025». Maybe there should be a switch somewhere (i.e. in a non-ignored part of the configuration?) that allows the administrator to deny such requests? Or we should trust that every user effectively will find a creative way to expose whatever he has rights to see, and the only weapon against such abuse is human-level policy and user education? Greetings, -- Gunnar Wolf - [EMAIL PROTECTED] - (+52-55)5623-0154 / 1451-2244 PGP key 1024D/8BB527AF 2001-10-23 Fingerprint: 0C79 D2D1 2C4E 9CE4 5973 F800 D80E F35A 8BB5 27AF _______________________________________________ Cherokee mailing list [email protected] http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
