[prev in list] [next in list] [prev in thread] [next in thread]
List: apache-httpd-users
Subject: Re: [users@httpd] Why the encoded url can't be used in the
From: Nick Kew <nick () webthing ! com>
Date: 2007-10-31 12:41:51
Message-ID: 20071031124151.1fcb3c1e () grimnir
[Download RAW message or body]
On Wed, 31 Oct 2007 17:57:25 +0800
ChiaTzung Liu -劉佳宗 <ChiaTzung.Liu@zyxel.com.tw> wrote:
> Hi..
>
> Did anyone try to set the encoded url? If I set
> "Alias /MyWeb/%A4%D1%A4%D1%B6%7D%A4%DF /i-data/e1cd5e28/book", then I
Apache unescapes URLs before applying aliases.
To do otherwise would open it up to a bunch of URL-based attacks.
--
Nick Kew
Application Development with Apache - the Apache Modules Book
http://www.apachetutor.org/
---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic