[EMAIL PROTECTED] RE:[EMAIL PROTECTED] how to prevent an executing from /tmp

2006-06-02 Thread Oliver.Schaudt
>Hi >Will this break file uploads using web forms? Only if you are using any other METHOD like GET HEAD POST [for uploads to a specific location you're using normally PUT] and you wnat to store this in /tmp. This is than no longer possible. [EMAIL PROTECTED] wrote: >> Hi! > >> Someone often u

Re: [EMAIL PROTECTED] RE:[EMAIL PROTECTED] how to prevent an executing from /tmp

2006-06-02 Thread Nick Kew
> > > >Someone often uploads files to /tmp and then executing in on the server > > with webserver user priveleges. How to prevent it? Mount /tmp, and anywhere else the server user has write access to, on a filesystem with noexec set. -- Nick Kew

Re: [EMAIL PROTECTED] RE:[EMAIL PROTECTED] how to prevent an executing from /tmp

2006-06-02 Thread nocturnal
Hi Will this break file uploads using web forms? Med vänliga hälsningar Stefan Midjich aka nocturnal [Swehack] http://swehack.se [EMAIL PROTECTED] wrote: Hi! Someone often uploads files to /tmp and then executing in on the server with webserver user priveleges. How to prevent it? Tha

[EMAIL PROTECTED] RE:[EMAIL PROTECTED] how to prevent an executing from /tmp

2006-06-02 Thread Oliver.Schaudt
>Hi! >Someone often uploads files to /tmp and then executing in on the server with >webserver user priveleges. How to prevent it? >Thanks, >G. One possibility is this: Order Deny,Allow #Deny from All Allow from All Order Deny,Allow Deny from all Allow from 12