Bugtraq mailing list archives

Re: Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy


From: dstinbox () gmail com
Date: 5 Sep 2008 16:43:12 -0000

I ran accross your post,
can you tell me how to harden the config file against this
 
would this do it ?
 
<Directory "<Directory "E:\infra\ ...">
        AllowOverride None
        Options None
        Order deny,allow
        Deny from all
  Allow from localhost
</Directory>


Current thread: