Bugtraq mailing list archives

Re: FrontPage + Apache + FreeBSD -Reply


From: RVM () CBORD COM (Bob McConnell)
Date: Mon, 29 Mar 1999 09:10:53 -0500


Gregory,

I'm assuming you implement this by assigning separate IP addresses to the two
virtual site names. Are the DNS servers returning the correct IP's for each of
them?

Bob McConnell


"Gregory A. Carter" <omni () DYNMC NET> 03/26/99 05:44pm >>>
On Fri, 26 Mar 1999, Paul Schandel wrote:

 . This is not a security issue.  Hence why they did not respond to you.
 .

No this is not correct, when I'm going to www.domain.com... instead of the
server pointing me at the root web of the virtual hosted site it brings me
to the root web of the whole server.  Sub webs have nothing to do with it.
I wouldn't care about the problem at all accept for the fact the when it
directs FrontPage Explorer to the main root web instead it also uses the
VIRTUAL WEBS permissions.  Hence as in my case I added a user to the
virtual web and pointed my web site to www.domain.com (the virtual web
alias), it brought up the MAIN web for the whole server but allowed me
access with the virtual webs permissions.  This is *definatly* a bug on
M$'s side here.  The extensions to at the LEAST recognize the
"ServerAlias" directive in apache and either #1 Go to the right web or #2
deny access to the main root web of the whole server with the virtual webs
usernames and passwords.



Current thread: