Vulnerability Development mailing list archives

Re: CGI source being exposed using "~"


From: peak () ARGO TROJA MFF CUNI CZ (Pavel Kankovsky)
Date: Tue, 9 May 2000 11:11:47 +0200


On Sun, 7 May 2000, Andrew Reisse wrote:

<Files ~ "^\~">

This matches *pathnames* starting with ~.

IMHO, the pattern should read "\~$" (I am not sure the backslash is
necessary but it does not hurt). I myself have configured my webserver
to deny all access to "(/\.|\~$|\.bak$|\.old$)".

--Pavel Kankovsky aka Peak  [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."


Current thread: