Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 293902

Use +SymLinksIfOwnerMatch instead of +FollowSymLinks option in .htaccess - Security

$
0
0

Security concern

FollowSymlinks does not protect against malicious links into other domain's directories.

Problem/Motivation

My host has tightened up its security settings and now forbids +FollowSymLinks option in .htaccess. This causes an error 500 when accessing the site. When they introduced this policy they automatically converted +FollowSymLinks to +SymLinksIfOwnerMatch. A drupal upgrade overwrote this change.

Affected platforms and systems

Proposed resolution

Change to +SymLinksIfOwnerMatch in Drupal core. It works just as well (on my host at least) and causes fewer problems. More information on the Sucuri blog at http://blog.sucuri.net/2013/05/from-a-site-compromise-to-full-root-acces...

Remaining tasks

Tests on other systems by those with more experience than I have.


Viewing all articles
Browse latest Browse all 293902

Trending Articles