Free hosting for free people.
TuxFamily is a non-profit organization that provides free services for projects and contents
dealing with the free software philosophy.
Read more
Forum activity
- Cannot access git repository with ssh:// in Fedora 41
- Unable to ftp into repositories.
- Impossible d'accéder par FTP
- un grand merci, je me sens déjà @home
- PHP 8.x
Latest projects
- Debian beginners handbook
- HyprLand Commander
- ESL Management System
- Serpent Twofish AES File Encrypter
- scienceforum
Getting help
Webmail
Panel access
Archives
- May 2024
- April 2024
- October 2023
- July 2023
- June 2023
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- February 2022
- December 2020
- September 2020
- November 2019
- October 2019
- August 2019
- May 2019
- April 2019
- June 2018
- April 2018
- January 2018
- June 2017
- April 2017
- February 2017
- October 2016
- April 2016
- November 2015
- September 2015
- August 2015
- June 2015
- April 2015
- March 2015
- January 2015
- November 2014
- July 2014
- June 2014
- May 2014
- April 2014
- March 2014
- February 2014
- December 2013
- July 2013
- June 2013
- May 2013
- April 2013
- March 2013
- January 2013
- December 2012
- June 2012
- April 2012
- March 2012
- January 2012
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- December 2010
- November 2010
- August 2010
- July 2010
- June 2010
- April 2010
- March 2010
- January 2010
- October 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- January 2009
- October 2008
- September 2008
- August 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- October 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- July 2006
- June 2006
- May 2006
- April 2006
- February 2006
- January 2006
News
Apache AddHandler moved to AddType due to security considerations
Posted on Sunday 29 March 2009
Hi,
Due to security considerations, AddHandler should not be used in apache configuration files. As uncovered by an old thread on the suphp mailing list, this would allow any files containing ".php" to be executed by php (for example example.php.jpg, trust me, this is not what you want ;) ).
As using AddHandler was sadly advised in our FAQ example, most of our hosted people were using it in their .htaccess. To fix this security flaw, we have added full support to AddType, modified our FAQ and run a script to widely and roughly modify all .htaccess files to retroactively fix the problem on TuxFamily.
If you were using a custom .htaccess file containing AddHander/AddType instructions, please check that everything is still working fine as our script may have introduced some side effects.
If you are automatically upgrading your website through rsync or such, please fix your local copy of .htaccess according to the new version of the FAQ.
However, we are not the only one to blame, because the Apache documentation is very unclear on this particular point, as you can see on the addhandler and addtype descriptions.
Your admins