[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] UID of script userid less than configuredminimum



 I would consider
any names generated by the command  cut -d":" -f1 /etc/passwd to be
reserved words until a new cgi-wrapper is tested and available.


Gulp... This is a rather far reaching bug!! If I'm digesting the situation correctly, it seems that whatever I name the directories that contain my cgi scripts, all one of my domain clients has to do is create a user with the same name (maliciously or accidentally) and all my scripts come to a screeching halt!!!

I've done a little testing and this does seem to be the case. What a bitch this would be to track down if you didn't know about it! Theoretically, my clients could even bring each other's scripts down if they felt so inclined. Imagine the catfights!

The only fix I can see for this would be to only keep your scripts in the web directory (I don't even want to know what happens when someone inevitably creates a 'web' user). This doesn't work for me because I want 3 different levels of access to this set of scripts I'm working on. I guess I could do 3 separate sites - UGH

What does this CGIWrap thing really do anyway? Is it keeping my clients from running each other's scripts? Accessing each other's files? Messing with the system? Anyone want to come to CGIWrap's defense or have you all uninstalled it ages ago?

Ta,
doug




. . . . . . . . . . . . . . . . . . . . . . . . . . . . .
. Doug Anarino                        Managing Director .
. http://Syntropo.Com/doug      http://Provincetown.Com .
. Doug@xxxxxxxxxxxxxxxx     http://ProvincetownShop.Com .
. . . . . . . . . . . . . . . . . . . . . . . . . . . . .