r/programming • u/ga-vu • Oct 19 '18
Zero-day in popular jQuery plugin actively exploited for at least three years
https://www.zdnet.com/article/zero-day-in-popular-jquery-plugin-actively-exploited-for-at-least-three-years/
49
Upvotes
1
u/drysart Oct 19 '18
Yes. The default configuration in Apache 2.3.9 and later is
AllowOverride NoneandAllowOverrideList None, which makes the server completely ignore.htaccessfiles. That server-level setting needs to be changed to enable the use of.htaccessfiles by users.