aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLouise Crow <louise.crow@gmail.com>2014-11-21 17:28:21 +0000
committerLouise Crow <louise.crow@gmail.com>2014-12-22 16:57:22 +0000
commitc359f1cf2e1fd7cd4359a75f1522d9ffdadb80d4 (patch)
treecaffcf892e1a78bb72c74025d94f35b8caec23d4
parentfbb25bdb29fcbbf982e5b1fa65ac87cabf838116 (diff)
Don't allow script execution from the cache directory
-rw-r--r--config/httpd.conf-example6
1 files changed, 6 insertions, 0 deletions
diff --git a/config/httpd.conf-example b/config/httpd.conf-example
index dc2e4966e..a7183e4cc 100644
--- a/config/httpd.conf-example
+++ b/config/httpd.conf-example
@@ -43,6 +43,12 @@ RewriteMap escape int:escape
RewriteCond %{DOCUMENT_ROOT}/views_cache/request/$2/$1/${escape:$3} -f
RewriteRule ^/request/((\d{1,3})\d*)/(response/\d+/attach/(html/)?\d+/.+) /views_cache/request/$2/$1/${escape:$3} [L]
+# Don't allow anything to execute from the cache
+<Directory "/var/www/alaveteli/public/views_cache">
+ Options -ExecCGI
+ SetHandler default-handler
+ AllowOverride None
+</Directory>
<IfModule mod_passenger.c>
# Set this to something like 100 if you have memory leak issues