Go Back   HostGator Peer Support Forums > Public Forums > Suggestions

Notices

Reply
 
Thread Tools
  #1  
Old 12-03-2007, 12:12 PM
Steve1943 Steve1943 is offline
Hatchling Croc
 
Join Date: Nov 2007
Posts: 4
Default Transparency re .htaccess restrictions

I've wasted a fair bit of my time and that of Support trying to implement and debug Apache commands (via .htaccess) only to eventually discover that the cause of the unexpected results (including 500 errors) was that you have wholly or partially disabled certain functions appearing in the official Apache manuals.

Upon reqeust, Support have subsequently either unblocked the command or suggested work arounds.

I'm not suggesting that blocking the commands is necessarily a bad idea (although usually it is given how easy it is with Apache to restrict consequences to a single file, directory, user etc).

However, some publicly available documentation about what you are blocking (and why) might save users and Support a ton of time and frustration.
Reply With Quote
  #2  
Old 12-06-2007, 05:23 AM
keyreviews keyreviews is offline
Hatchling Croc
 
Join Date: Aug 2007
Posts: 36
Default Re: Transparency re .htaccess restrictions

Which commands are you finding blocked?
__________________
Thomas Tremain
Internet Consultant
Offline cPanel Backups
Web Hosting Reviews
Reply With Quote
  #3  
Old 12-06-2007, 09:01 AM
Goddess Dix's Avatar
Goddess Dix Goddess Dix is offline
King Croc
 
Join Date: Aug 2006
Location: KS, USA
Posts: 1,498
Default Re: Transparency re .htaccess restrictions

Quote:
Originally Posted by Steve1943 View Post
However, some publicly available documentation about what you are blocking (and why) might save users and Support a ton of time and frustration.
i understand your frustration (and expectations that support should know what functions are blocked and why, which doesn't seem unreasonable).

but publically announcing exactly which functions will work and which won't is a very, very bad idea for security. the more info that's publically available on your server configuration, the easier it would be to exploit.
Reply With Quote
  #4  
Old 12-06-2007, 10:41 PM
special's Avatar
special special is offline
Junior Croc
 
Join Date: Dec 2007
Location: Netherlands
Posts: 111
Default Re: Transparency re .htaccess restrictions

Quote:
Originally Posted by Goddess Dix View Post
i understand your frustration (and expectations that support should know what functions are blocked and why, which doesn't seem unreasonable).

but publically announcing exactly which functions will work and which won't is a very, very bad idea for security. the more info that's publically available on your server configuration, the easier it would be to exploit.
Well that isent really true, if they take so much trouble to get you. They will get you even if he posts it or not. Its yust a mather of how his coding is secure and how much the target wants to attack him.
__________________
Me Love www.animeresource.org
Reply With Quote
  #5  
Old 12-07-2007, 08:39 AM
Goddess Dix's Avatar
Goddess Dix Goddess Dix is offline
King Croc
 
Join Date: Aug 2006
Location: KS, USA
Posts: 1,498
Default Re: Transparency re .htaccess restrictions

Quote:
Originally Posted by special View Post
Well that isent really true, if they take so much trouble to get you. They will get you even if he posts it or not. Its yust a mather of how his coding is secure and how much the target wants to attack him.
well, actually reading the thread, one could see we were talking about hg publically posting details of their apache configuration, which would be moronic IMO.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 09:30 AM.