Bugtraq mailing list archives

Re: Apache 1.3.27 mod_proxy security issue


From: Michael Shigorin <mike () osdn org ua>
Date: Tue, 29 Jul 2003 12:34:56 +0300

On Tue, Jul 22, 2003 at 05:30:39PM -0500, William A. Rowe, Jr. wrote:
As described in the default configuration, open proxies are never
recommended [from Apache 1.3.27 conf/httpd.conf-dist];

[skip]

#        Allow from .your-domain.com

Is it reasonable to use something intentionally broken like
.your_domain.com (not even example.*) in configuration samples
like this one?

-- 
 ---- WBR, Michael Shigorin <mike () altlinux ru>
  ------ Linux.Kiev http://www.linux.kiev.ua/

Attachment: _bin
Description:


Current thread: