On Thu, Dec 11, 2008 at 6:23 PM, Christopher Drost
<[email protected]> wrote:
>
> This is false, as far as I can tell -- if you allow FollowSymLinks,
> then the malicious user doesn't care about the <Directory />
> conditional. (Per mod/core.html#options :: "Even though the server
> follows the symlink it does not change the pathname used to match
> against <Directory> sections.")

How do you get out from under / with a symlink?


-- 
Eric Covener
[email protected]

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to