Sergio Cuéllar Valdés dijo [Thu, Mar 27, 2008 at 04:00:00PM -0600]:
> Hi Gunnar,
> 
> I think it should be moved to /usr/bin, for the reason you have
> exposed. But if the -p is not implemented yet, the default port is
> still 80 in the example you gave. But you cannot bind that port as
> normal user ? Can you ?

No, you cannot yet bind. But I believe in Álvaro's word - Trust him,
he will fix this ;-)

I'm just plaing a bit with the security implications... Say, Joe
Random User gets a shell account in your shared host, and just to test
it, runs «cherokee -r / -p 1025». Maybe there should be a switch
somewhere (i.e. in a non-ignored part of the configuration?) that
allows the administrator to deny such requests? Or we should trust
that every user effectively will find a creative way to expose
whatever he has rights to see, and the only weapon against such abuse
is human-level policy and user education?

Greetings,

-- 
Gunnar Wolf - [EMAIL PROTECTED] - (+52-55)5623-0154 / 1451-2244
PGP key 1024D/8BB527AF 2001-10-23
Fingerprint: 0C79 D2D1 2C4E 9CE4 5973  F800 D80E F35A 8BB5 27AF
_______________________________________________
Cherokee mailing list
[email protected]
http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee

Reply via email to