On Wed, 6 Mar 2013 13:09:20 +0000 Brett Parker iDunno@sommitrealweird.co.uk allegedly wrote:
lighttpd isn't my favourite, and I wouldn't run it on anything internet facing...
Why not? I have been doing so for years. Lighty has had memory leak problems (see the slow request vulnerability of a few years back for example) which could lead to DOS, but I don't recall it being particularly full of any more holes than any other internet facing server software.
I've seen a fair few holes in lighttpd, I don't actually recommend it for anything facing the general internet, but it is small...
Can you point to some examples? I may need to check my configurations.
Mick
---------------------------------------------------------------------
blog: baldric.net gpg fingerprint: FC23 3338 F664 5E66 876B 72C0 0A1F E60B 5BAD D312
---------------------------------------------------------------------