You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@httpd.apache.org by amit khatri <am...@hotmail.com> on 2002/03/11 21:25:30 UTC

give the solution,URGENT

please give the solution , we need it badly ,there is no security hole 
because we are providing authentication.
     please tell the solution


>From: "Joshua Slive" <jo...@slive.ca>
>Reply-To: users@httpd.apache.org
>To: <us...@httpd.apache.org>
>Subject: RE: compiled apache with EXTRA_CFLAGS=-DBIG_SECURITY_HOLE but ...
>Date: Mon, 11 Mar 2002 15:18:49 -0500
>
>
> > From: amit khatri [mailto:amitjkhatri@hotmail.com]
>
> > i  downloaded apache and added the following
> >           EXTRA_CFLAGS=-DBIG_SECURITY_HOLE
> > to src/Configuration and compiled it but when
> >                 apachectl start
> >    is given the foll error message :
> >
> >     "Apache is not designed to to serve pages while running as root.
> >     if you still want to serve the pages as root then
> >     add -DBIG_SECURITY_HOLE to your EXTRA_CFLAGS line in your
> >     src/Configuration file and rebuild the server."
> > what could be the problem???
>
>If you use ./configure to build apache, then editing src/Configuration will
>have no effect.
>
>I would give you instructions on how to do it properly, but what you are
>trying to do falls under the category "If you can't figure it out, you
>shouldn't be doing it."  And, in fact, it also falls under the category
>"Even if you can figure it out, you shouldn't be doing it".
>
>The only time I would even *consider* making that change is if you have a
>small, internal network, where you absolutely trust all your users and 
>there
>is no connection whatsoever to the Internet.
>
>Joshua.
>
>
>---------------------------------------------------------------------
>The official User-To-User support forum of the Apache HTTP Server Project.
>See <URL:http://httpd.apache.org/userslist.html> for more info.
>To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
>For additional commands, e-mail: users-help@httpd.apache.org
>




_________________________________________________________________
Join the world’s largest e-mail service with MSN Hotmail. 
http://www.hotmail.com


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


RE: give the solution,URGENT

Posted by Joshua Slive <jo...@slive.ca>.
> From: amit khatri [mailto:amitjkhatri@hotmail.com]

> please give the solution , we need it badly ,there is no security hole
> because we are providing authentication.
>      please tell the solution

I replied to him directly.  No point having a bad idea like this archived
for posterity, but if he wants to screw up his system, I'm not going to stop
him.

Joshua.


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


RE: give the solution,URGENT

Posted by Bryan Henry <br...@mail.utexas.edu>.
He DID...

>From: "Joshua Slive" <jo...@slive.ca>
>> If you use ./configure to build apache, then editing 
>>src/Configuration will have no effect.

be nice.

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org