LWN.net Logo

Security quotes of the week

Security quotes of the week

Posted Oct 4, 2012 19:08 UTC (Thu) by spender (subscriber, #23067)
In reply to: Security quotes of the week by ftc
Parent article: Security quotes of the week

It appears to me to just be a problem of muddy definitions. With the following:

webserver: the OS environment/filesystem/etc
off-site: not via HTTP

it should make more sense (as it seems you agree). It's not clear that even access control could help however if a "plugin" is some kind of interpreted script, using the same interpreter (executing in the context of Apache via mod_php.so) that would be accessing wp-config.php normally. Control over the interpreter is pretty much game over.

-Brad


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds