>Getting a security audit is a good idea. There are too many configurable
>things in Apache that can turn into security holes - e.g. the Apache.org
>exploit reported today. 

No doubt there is lots of room for mistakes in configuring Apache,
the exploit is not an Apache configuration mistake per se but a site
configuration mistake. It started with the http and ftp servers being
the same and there being a downloadable directory accessible by http.
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to