Re: [cgiwrap-users] "Feature" request during next release
Brought to you by:
nneul
From: Jo R. <jr...@ne...> - 2007-11-09 19:29:31
|
On Nov 4, 2007, at 11:10 AM, Tuc at T-B-O-H.NET wrote: > Basically this stems from one CGI package I'm installing throwing > GARBAGE that they shouldn't at STDERR which causes the system to stop. > So I'm going to compile up a CGIWRAP with "--without-redirect- > stderr" and > put it as another name for just that VH. Frankly, "--with-redirect-stderr" is a major security problem and has no useful function that I'm aware of. Why don't you simply use that as standard? I would personally push to drop/deprecate/warn-loudly-against that mis-feature. I mean, it's my favorite way to get db passwords and stuff out of other people's websites, but that's not actually a feature for anyone not trying to hack something. -- Jo Rhett Net Consonance : consonant endings by net philanthropy, open source and other randomness |