General Apache Information
This book is not for the hardcore Apache administrators. Included here are a few important directives that you might find useful. If you have access to your Apache server, you can check your settings. If not, please consult your host.
INCLUDES
Options +Includes
Turns on the capability to have SSI (Server Side Includes) in files.
IncludesNOEXEC
Options +IncludesNOEXEC
This turns on the permission to use SSI. It prevents the use of #exec
or someone using #include
to load CGI programs. This is important to remove the bulk of risks associated with the Server Side Include attack.
If you are interested in administering Apache, I suggest the Apache Administrator's Handbook by Rich Bowen, Allan Liska, and Daniel Lopez Ridruejo.
Last word: REMOVE FrontPage extensions from your server unless you absolutely need them.