1 |
Path: news.suika!not-for-mail
|
2 |
From: "$B<cMU(B" <w@suika.fam.cx>
|
3 |
Newsgroups: suika.admin
|
4 |
Subject: suEXEC $B$NF3F~$H$=$l$KH<$&@_DjJQ99$N$*4j$$(B
|
5 |
Date: Mon, 15 Apr 2002 18:41:38 +0900
|
6 |
Lines: 61
|
7 |
Message-ID: <usj.guls9p.yx73.MFMMpm%w@suika.fam.cx>
|
8 |
NNTP-Posting-Host: fb1042.noc.toyama.nsk.ne.jp
|
9 |
X-Trace: suika.fam.cx 1018863715 5813 61.213.217.170 (15 Apr 2002 09:41:55 GMT)
|
10 |
X-Complaints-To: news@suika.fam.cx
|
11 |
NNTP-Posting-Date: 15 Apr 2002 09:41:55 GMT
|
12 |
X-Moe: "$BGpLZ04(B"
|
13 |
X-Brother: "$B$;$C$-!<$5$^(B$(O&=(B"; as=elder
|
14 |
User-Agent: send.pl/2.01 jcode.pl (Id: jcode.pl,v 2.11 1999/12/26 17:16:47
|
15 |
utashiro Exp ) Jcode.pm/0.79 field_name/user-agent
|
16 |
format/mail-rfc2822
|
17 |
"$B=(4]%(%G%#%?(B"/3.08
|
18 |
MS-IME/7.1.0 (Microsoft\(\B$\(\O\)\*\(\B IME 2000)
|
19 |
Message-pm/1.09 Perl/5.6.1 (MSWin32-x86-multi-thread)
|
20 |
MSWin32/4.0
|
21 |
X-Copyright: Public Domain.
|
22 |
X-Weather: $B:#$NIY;3$O(B$(O&i$B$J$^$L$k$$!#(B
|
23 |
Xref: news.suika suika.admin:178
|
24 |
|
25 |
$B7s$M$F$+$i:F;0$7$D$3$/?=$7$F$*$j$^$9$H$*$j!"(B suEXEC
|
26 |
$B$rF3F~$7$^$9!#$=$l$K$h$j!"$?$V$s$$$^(B suika.fam.cx $B$GF0$$$F$$$k(B
|
27 |
CGI/SSI $B$OF0$+$J$/$J$k$H;W$&$N$G!"@_DjJQ99$r$*4j$$$7$^$9!#(B
|
28 |
|
29 |
1. SSI $B$K$D$$$F(B
|
30 |
|
31 |
$B$$$^(B suika.fam.cx $B$G(B SSI $B$r;H$C$F$$$k?M$,(B ($B$o$+$P0J30$K(B) $B$$$k$N$+(B
|
32 |
$B$$$J$$$N$+CN$j$^$;$s$+$i!"4JC1$K@bL@$7$^$9!#>\$7$/CN$j$?$1$l$P(B
|
33 |
$B<+J,$GD4$Y$k$+$o$+$P$KJ9$$$F2<$5$$!#(B
|
34 |
|
35 |
1. $B$$$^$O(B default on $B$G$9$,!"(B default off $B$K$9$k$N$G!"(B
|
36 |
.htaccess $B$K;H$($k$h$&$K=q$$$H$/I,MW$,$"$j$^$9!#(B
|
37 |
2. $B<+J,$N%G%#%l%/%H%j$h$j>e$NAjBP;2>H(B ($BNc(B: ../foo/bar)
|
38 |
$B$H$+@dBP;2>H(B ($BNc(B: /usr/bin) $B$,;H$($J$/$J$j$^$9!#(B
|
39 |
3. $B0z?t$D$-L?Na<B9T(B ($BNc(B: <!--#exec cmd="foo.cgi foo"-->)
|
40 |
$B$,;H$($J$/$J$j$^$9!#(B ($B$3$l$OITJX$@$J$"!#(B)
|
41 |
|
42 |
2. CGI $B$K$D$$$F(B
|
43 |
|
44 |
1. CGI $B$O=jM-<T8"8B$G<B9T$5$l$^$9!#%Q!<%_%C%7%g%s$rE,Ev$K(B
|
45 |
$B@_Dj$7$F$/$@$5$$!#(B (777 $B$H$+(B 600 $B$H$+$$$&$"$l$G$9!#(B)
|
46 |
|
47 |
$B$$(B: CGI $B$H4XO"%U%!%$%k$N=jM-<T$OK\Mh$N=jM-<T(B (nobody
|
48 |
$B$H$+$8$c$J$/$F!#(B) $B$K$7$F2<$5$$!#(B ($BFC$K(B CGI $B$,@8@.(B
|
49 |
$B$9$k%G!<%?!&%U%!%$%k$KCm0U!#(B)
|
50 |
$B$m(B: CGI $B$O(B 755 $BJU$j$K$7$H$$$F2<$5$$!#(B ($B8=>u$G$O(B
|
51 |
other $B$N(B x ($B<B9T(B) $B$,N)$C$F$F(B 557 $B$H$+!"(B 777 $B$H$+(B
|
52 |
$B$K$J$C$F$k$s$8$c$J$$$G$9$+$M(B? $B<B9T8"8B$O(B
|
53 |
$B=jM-<T$@$1$G(B OK $B$G$9!#(B)
|
54 |
$B$O(B: $B4XO"%U%!%$%k$O(B 600 ($B=jM-<T$,FI$_=q$-2DG=(B) $B$G==J,(B
|
55 |
$B$G$9!#(B ($B8=>u$G$O(B 606 $B$H$+(B 666 (world-writable)
|
56 |
$B$K$J$C$F$k$H;W$o$l!#(B)
|
57 |
$B$K(B: CGI $B$N(B setUID $B%S%C%H$rN)$F$F$$$l$P!"$=$l$O(B
|
58 |
$BMn$H$7$F2<$5$$$J!#ITMW$G$9!#(B
|
59 |
$B$[(B: $B$"$^$jL5$$$H$O;W$$$^$9$,!"(B CGI script $BFbIt$G(B
|
60 |
$B8=>u$N%Q!<%_%C%7%g%s$K0MB8$7$?=hM}$r$7$F$$$k$b$N(B
|
61 |
($BNc$($P!"%G!<%?!&%U%!%$%k$r:n@.$7$?;~$K!"$=$N(B
|
62 |
$B%Q!<%_%C%7%g%s$r(B 666 $B$KJQ$($k$H$+!#(B) $B$OI,MW$K(B
|
63 |
$B1~$8$F=$@5$7$?J}$,NI$$$H;W$$$^$9!#(B
|
64 |
|
65 |
3. PHP $B$K$D$$$F(B
|
66 |
|
67 |
PHP $B$O=$@5ITMW$N$O$:$G$9(B($B;EMM>e(B)$B!#5U$K$$$&$H:#2s$NJQ99(B
|
68 |
$B$N287C$O<u$1$^$;$s!#(B
|
69 |
|
70 |
$B7h9T(B($BFf(B)$B4|F|$O!"(B4$B7nKv$NO"5Y$+!"(B5$B7n;O$a$NO"5Y$NA0H>$r(B
|
71 |
$BM=Dj$7$F$$$^$9!#(B ($B8eH>$O%F%9%H$J$N(B:-<) $B$b$C$H6qBNE*$JF|$O(B
|
72 |
$BA0F|H/I=$G$$$$$G$9$+$M(B? ($BCY$$$+$J(B?)
|
73 |
|
74 |
$B$J$K$+ITL@$JE@$,$"$C$?$i$o$+$P$^$G$*$?$:$M2<$5$$!#(B
|
75 |
|
76 |
$B$"!"$=$l$H!"G0$N$?$aIU$12C$($F$*$-$^$9$,!"(B suEXEC $B$O(B
|
77 |
$B0BA4EY6/2=$K$O$J$j$^$9$,!"@dBP0BA4$G$O$J$$$3$H$O(B
|
78 |
$BJQ$o$i$J$$$N$G!">o$KCm0U$7$FD:$-$?$$$3$H$b:#$^$GDL$j$G$"$j$^$9!#(B
|
79 |
$B$^$?!"$3$N5!2q$K!"(B CGI script $B$J$I$N0BA4@-$r:FE@8!$7$F(B
|
80 |
$B$$$?$@$1$l$P$H;W$C$F$*$j$^$9!#(B ($B$=$3$i$GG[I[$5$l$F$$$k(B
|
81 |
CGI script $B$J$I$G$b!"%/%m%9%5%$%H%9%/%j%W%A%s%0@H<e@-(B
|
82 |
$B$_$?$$$JLdBj$,H/8+$5$l$F$$$k$b$N$b7k9=$"$j$^$9$+$i!#(B)
|
83 |
|
84 |
$B$o$+$P!#(B
|
85 |
|