[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Removing stupid HTTP methods from Apache



Hi Anne,

> I'm running Apache on a Woody machine, and I can't figure
> out for the life of me how to disable certain insecure HTTP
> methods like PROPFIND and PUT.

I hope this helps:

http://www.daemon.be/~maarten/apache-1.3.27-stripping.patch

Limit and LimitExcept are also possible solutions, but you can't use
them to disable all methods.  Some are immune to this :-)

Cheers,
Maarten

-- 
Maarten Van Horenbeeck        Ubizen
Network Security Analyst      We Secure e-Business
Phone   +32 16 28 70 00       http://www.ubizen.com
Fax     +32 16 28 71 00       http://www.onlineguardian.com

The information transmitted is intended only for the person
or entity to which it is addressed and may contain confidential
and/or privileged material. If you are not the intended recipient,
please contact the sender by E-Mail return and then delete this
message from your system. You should not copy or use it or
disclose its contents to any other person. If any part of this
message is illegible or if you suspect that the message may
have been intercepted or amended, please contact the sender.
Ubizen N.V. cannot accept any responsibility for the accuracy
or completeness of this message without further investigation.



Reply to: