3 ms·
All this tells me is that preventing directory traversals can only be done by checking absolute file paths are within a bounded range, and nothing else.
by x-complexity 3y ago
All this tells me is that preventing directory traversals can only be done by checking absolute file paths are within a bounded range, and nothing else.
- nonameiguess 3y agoRunning the server as a service account that can only read its own directories, running it in a chroot, running it in a mount and pid namespace, using SELinux to further restrict what files it can read even in principle. Of course, if you're trying to go superminimal anyway, it's not that big a deal to create a server that doesn't even have sensitive data on it. You can make init simply mount a root filesystem that only has busybox and whatever files you want to serve and starts up the httpd process and nothing else. Turn Linux into a unikernel basically. If you compile busybox yourself, you're also able to remove all the subcommands you don't actually need.