LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-22-2015, 10:35 PM   #1
dcsst28
LQ Newbie
 
Registered: Mar 2012
Distribution: Slackware, Fedora
Posts: 18

Rep: Reputation: Disabled
Exclamation All files under Apache 2.4 webserver "cgi-bin" directory open to Internet


Hello,

I have a problem. The website I am hosting is leaking files on the Internet, and I do not know why. I am running Apache 2.4. The permissions on the cgi-bin directory are the same as all other directories under apache24/, but every file in the cgi-bin directory is viewable by anybody. The other thing I do not understand is this: I have virtual hosts set up, and there is no cgi-bin directory under those sites. It is only located under the default apache24/ directory. So, how can anyone even access the cgi-bin directory? Anyone have any ideas? There is no sensitive information in any of the files under cgi-bin, but if people can view those files, then what else can they view?

Thanks.
 
Old 01-24-2015, 03:48 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by dcsst28 View Post
I am running Apache 2.4. The permissions on the cgi-bin directory are the same as all other directories under apache24/, but every file in the cgi-bin directory is viewable by anybody.
What are those permissions exactly?

Quote:
Originally Posted by dcsst28
I have virtual hosts set up, and there is no cgi-bin directory under those sites. It is only located under the default apache24/ directory. So, how can anyone even access the cgi-bin directory?
Are you intending to serve .cgi files?
Since you have virtualhosts setup, you could "deny all" in the conf for the cgi-bin directories. Google/other for examples
What OS? Self-hosted or otherwise? How was Apache installed and by what method (package manager/compiled from source/you got it that way)?

Quote:
Originally Posted by dcsst28
but if people can view those files, then what else can they view?
See first reply/Question.
 
Old 01-24-2015, 05:23 PM   #3
dcsst28
LQ Newbie
 
Registered: Mar 2012
Distribution: Slackware, Fedora
Posts: 18

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by Habitual View Post
What are those permissions exactly?

Are you intending to serve .cgi files?
Since you have virtualhosts setup, you could "deny all" in the conf for the cgi-bin directories. Google/other for examples
What OS? Self-hosted or otherwise? How was Apache installed and by what method (package manager/compiled from source/you got it that way)?

See first reply/Question.
Hello.

The permissions of all directories under apache24 (cgi-bin, data, error, icons) are as follows:

drwxr-xr-x

The permissions of all files under cgi-bin (and other directories) are as follows:

-rw-r--r--

No, I am not intending to serve .cgi files. Like I mentioned before, there are no cgi-bin directories in the paths of my virtual hosts; the only cgi-bin directory is in the default apache24 directory defined by httpd.conf. This is overridden by the virtual hosts, however.

So, I just realized I posted a question in a Linux forum about a FreeBSD box. So, not sure if this is going to go any further, but the OS is FreeBSD 10.1-RELEASE. I am hosting the website. I installed Apache 2.4 from the ports tree. I compiled it from source.

I am reading the results from the Google query link you sent.

Thanks.
 
  


Reply

Tags
access, apache, leak, virtual host, websites



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
script using "/usr/bin/cat error" produces "cannot open" in cron Dcrusoe Programming 6 07-22-2009 03:30 PM
"apache" user in cgi-bin scripts cool47 Linux - Server 3 08-10-2008 05:27 PM
"Permission denied" and "recursive directory loop" when searching for string in files mack1e Linux - Newbie 5 06-12-2008 07:38 AM
cgi-bin: "enable to create directory" xpucto Linux - Server 3 05-16-2007 09:09 AM
cgi-bin: "attempt to invoke directory as script" hamish Linux - Software 0 12-09-2004 12:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration