Solved

CGI SECUIRTY

Posted on 2003-12-02
1
190 Views
Last Modified: 2013-12-25
Hi Yall
Ive got a cgi "e-greeting card" located here.

http://www.21stcenturyspace.co.uk/card.html

i havent modfied it at all although there is a directory that contains the card gifs on the server thats CHMOD'd 777

the html card is also written to this directory for the recipient to view.

Does anyone know if there are any security issues related to this directory.


Cheers

MM
0
Comment
Question by:metalmickey
1 Comment
 
LVL 6

Accepted Solution

by:
aolXFT earned 125 total points
ID: 9860663
If it is on a shared server it can be a security risk to have it there.

It would be safer to put it outside the web-server-tree.

If you are using apache, you can mod the config to not allow any access to that directory, by the webserver. (Your CGI scripts will still be able to read and write to that dir)

The biggest problem would be people putting code into that directory, leading to execution of aribitory code.
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It is becoming increasingly popular to have a front-page slider on a web site. Nearly every TV website,  magazine or online news has one on their site, and even some e-commerce sites have one. Today you can use sliders with Joomla, WordPress or …
In this tutorial I will show you how to provide a dynamic RTF document on your website generated with data from your database. For this tutorial you will need Microsoft Word or WordPad, WhizBase and Microsoft Access. In this tutorial I will show …
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question