corbeeresearch Posted August 31, 2010 Share Posted August 31, 2010 If you enable mod_rewrite, does it creates insecurity problems? My friend says on a VPS, when you enable mod_rewrite, the whole htdocs will become writable. Is this true? And if it is, how do you fix it? Thanks Quote Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/ Share on other sites More sharing options...
trq Posted August 31, 2010 Share Posted August 31, 2010 My friend says on a VPS, when you enable mod_rewrite, the whole htdocs will become writable. Is this true? Your friend doesn't know what they are talking about. Quote Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105601 Share on other sites More sharing options...
corbeeresearch Posted August 31, 2010 Author Share Posted August 31, 2010 So there are no cases of insecurites if mod_rewrite is enabled? The server uses Apache 2.2 Quote Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105604 Share on other sites More sharing options...
trq Posted August 31, 2010 Share Posted August 31, 2010 There is nothing inherently insecure about having mod_rewrite enabled, that's not to say it is secure either. Like most things to relating to servers, care must be taken to configure it properly. Quote Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105607 Share on other sites More sharing options...
corbeeresearch Posted August 31, 2010 Author Share Posted August 31, 2010 Thanks! I got clarified a lot after reading your post Quote Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105614 Share on other sites More sharing options...
PFMaBiSmAd Posted August 31, 2010 Share Posted August 31, 2010 There are not very many ways that you can write to a server's disk without some kind of authorization or a helper service/application/script present on the server to perform the action. I would recommend that you ask your friend for a verifiable example or a working demonstration of how he believes this can be accomplished. Just a general unsubstantiated statement that enabling mod_rewrite allows writing somewhere on a server's disk is, well, unsubstantiated. Quote Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105619 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.