View previous topic :: View next topic |
Author |
Message |
dhaova n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 18 May 2005 Posts: 1
|
Posted: Wed May 18, 2005 2:25 am Post subject: Is posting a server's .config; apache confs a large risk? |
|
|
I'm currently completing an undergraduate thesis that involves building a webserver based on Gentoo Linux. Part of the content it will serve is an illustrated guide to its creation. Assuming that I don't give out shell access, is there any significant security risk to listing the server's kernel .config and Apache configuration files? I'm a pretty confident Linux user, but a near-total n00b when it comes to security...
Thanks :D |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
xbmodder Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
Joined: 25 Feb 2004 Posts: 404
|
Posted: Wed May 18, 2005 3:39 am Post subject: |
|
|
Its not a bad idea to post you .config file unless your extremely paranoid. Someone could find that you have an insecure kernel module. Then again the kernel is amazingly secure. I think its fine. Apache confs can be ok, BUT! BE CAREFUL! That you must be careful of not posting secret-directorys etc. _________________ http://xbmodder.us/ |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|