On Thu, Dec 11, 2008 at 6:23 PM, Christopher Drost <[email protected]> wrote: > > This is false, as far as I can tell -- if you allow FollowSymLinks, > then the malicious user doesn't care about the <Directory /> > conditional. (Per mod/core.html#options :: "Even though the server > follows the symlink it does not change the pathname used to match > against <Directory> sections.")
How do you get out from under / with a symlink? -- Eric Covener [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
