corbeeresearch Posted August 31, 2010 Share Posted August 31, 2010 If you enable mod_rewrite, does it creates insecurity problems? My friend says on a VPS, when you enable mod_rewrite, the whole htdocs will become writable. Is this true? And if it is, how do you fix it? Thanks Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/ Share on other sites More sharing options...
trq Posted August 31, 2010 Share Posted August 31, 2010 My friend says on a VPS, when you enable mod_rewrite, the whole htdocs will become writable. Is this true? Your friend doesn't know what they are talking about. Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105601 Share on other sites More sharing options...
corbeeresearch Posted August 31, 2010 Author Share Posted August 31, 2010 So there are no cases of insecurites if mod_rewrite is enabled? The server uses Apache 2.2 Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105604 Share on other sites More sharing options...
trq Posted August 31, 2010 Share Posted August 31, 2010 There is nothing inherently insecure about having mod_rewrite enabled, that's not to say it is secure either. Like most things to relating to servers, care must be taken to configure it properly. Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105607 Share on other sites More sharing options...
corbeeresearch Posted August 31, 2010 Author Share Posted August 31, 2010 Thanks! I got clarified a lot after reading your post Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105614 Share on other sites More sharing options...
PFMaBiSmAd Posted August 31, 2010 Share Posted August 31, 2010 There are not very many ways that you can write to a server's disk without some kind of authorization or a helper service/application/script present on the server to perform the action. I would recommend that you ask your friend for a verifiable example or a working demonstration of how he believes this can be accomplished. Just a general unsubstantiated statement that enabling mod_rewrite allows writing somewhere on a server's disk is, well, unsubstantiated. Link to comment https://forums.phpfreaks.com/topic/212172-does-mod_rewrite-creates-security-problems/#findComment-1105619 Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.