Hi,
we use LST 4.1RC4
We set check symbolic link on litespeed and on apache configuration we setup symbolic link only if owner match.
Under security on lst we have:
File Access
Follow Symbolic Link Yes
Check Symbolic Link Yes
Required Permission Mask 000
Restricted Permission Mask 000
and under Access Denied Directories:
/
/etc/*
/dev/*
$SERVER_ROOT/conf/*
$SERVER_ROOT/admin/conf/*
One website was hacked and was created a symbolic link point to /
It works and show all content of /
I think this is a big security problem.
We also setup under Access Denied Directories value /* but nothing works and all dir and files under / are visibile.
Waiting for your reply
Regards
we use LST 4.1RC4
We set check symbolic link on litespeed and on apache configuration we setup symbolic link only if owner match.
Under security on lst we have:
File Access
Follow Symbolic Link Yes
Check Symbolic Link Yes
Required Permission Mask 000
Restricted Permission Mask 000
and under Access Denied Directories:
/
/etc/*
/dev/*
$SERVER_ROOT/conf/*
$SERVER_ROOT/admin/conf/*
One website was hacked and was created a symbolic link point to /
It works and show all content of /
I think this is a big security problem.
We also setup under Access Denied Directories value /* but nothing works and all dir and files under / are visibile.
Waiting for your reply
Regards