in reply to Re: Re: Re: Re: Re: Re: Re: Re: mod_perl and shared environments don't mix - do they?
in thread mod_perl and shared environments don't mix - do they?
I haven't tried it, but with mod_perl a user ought to be able to modify his/her virtual host document root and mess with other users' stuff
You're thinking of adding things like an access handler or filter to someone else's stuff? You can only change that sort of configuration during startup, which would require you to have admin privileges on the server. After startup, docroot can't be changed.
A user might be able to bypass bandwidth throttling too
If you give people just Apache::Registry access and no use of .htaccess files they would not be able to, since it would be too late in the request for that. They could skip a cleanup or logging handler though.
Would it be impossible for a mod_perl script to persist in the apache child and monitor information passing to and from the sites of other users?
Not really. Your code ends when the request ends. However, you could take advantage of Perl's unprotected nature to globally redefine the print function or change the Apache::Registry handler function to do something completely different. So again, wide open for exploits, but all on the perl side. None of it related directly to the apache API.
|
---|
Replies are listed 'Best First'. | |
---|---|
Re^10: mod_perl and shared environments don't mix - do they?
by Aristotle (Chancellor) on Aug 11, 2003 at 21:19 UTC | |
Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: mod_perl and shared environments don't mix - do they?
by bean (Monk) on Aug 11, 2003 at 19:57 UTC |