From owner-freebsd-ports Sun Feb 3 9:47:50 2002 Delivered-To: freebsd-ports@freebsd.org Received: from pop3.inglobe.ch (195-048-204-045.net.ikg.ch [195.48.204.45]) by hub.freebsd.org (Postfix) with ESMTP id 16D2037B404 for ; Sun, 3 Feb 2002 09:47:42 -0800 (PST) Received: from levais.imp.ch (157.161.4.66) by pop3.inglobe.ch with MERCUR-SMTP/POP3/IMAP4-Server (v3.30.09 AS-0098309) for ; Sun, 3 Feb 2002 18:47:29 +0100 Date: Sun, 3 Feb 2002 18:47:51 +0100 (CET) From: Martin Blapp X-X-Sender: To: , , , , , , , Cc: Subject: Testers needed (apache mod_frontpage improved 1.6) (DSO) Message-ID: <20020203182945.H776-100000@levais.imp.ch> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Reply-To: mb@reigoldswil.ch Sender: owner-freebsd-ports@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hi all, As you may have noted, the "Improved mod frontpage" project hasn't had much news in the last year. I upgraded now this module, to have FP2002 support and to have a true DSO install. It can now be installed together with any binary apache 1.3.x. I also made the web administration a "opt in", tunable like FrontpageEnable as FrontpageAdminEnable, or FrontpageAdminDisable. The admin is disabled per default. I also fixed some very old bugs, and tested it carefully. For the web admin there is a new wrapper, which is called by the apache user and is _not_ SUID root. It just returns all static content like .gif, .html, .css and .js I'd be happy if you could test the features and read the changes I made. There are still some very ugly parts in the code, which I'd like to replace next week. -> Remove strcat() and add a lot more checks. But there are some main checks to be sure that nothing can be exploited. The new wrapper does run under the apache user only so we are safe for some way. Thank you for testing ;-) Distfile: --------- http://people.freebsd.org/~mbr/distfiles/mod_frontpage-1.6.tar.gz FreeBSD Port: ------------- http://people.freebsd.org/~mbr/distfiles/mod_frontpage-port.tgz The old module can be found on: ftp://ftp.edo.uni-dortmund.de/pub/mod_frontpage Martin Martin Blapp, ------------------------------------------------------------------ Improware AG, UNIX solution and service provider Zurlindenstrasse 29, 4133 Pratteln, Switzerland Phone: +41 061 826 93 00: +41 61 826 93 01 PGP Fingerprint: B434 53FC C87C FE7B 0A18 B84C 8686 EF22 D300 551E ------------------------------------------------------------------ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ports" in the body of the message