[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Re: [Raq3] File permissions- rejected from admin



Just got off the phone with Cobalt Tech support.

Yet another issue with Update: All System 3.0.1-6168 
[This update resolves a security issue with Frontpage extensions. 
Prior to this patch it would be possible to run CGI scripts as a 
user with higher privilages than the owner of a web site.]

If you don't run FrontPage DO NOT INSTALL THIS UPDATE!!!!!!!!!!!
It will recursively run down your site directories and change the
group ownership to NOBODY. In my case this broke cgi scripts and
other apps on 10 sites. 

The update is being pulled from the Cobalt site and a new patch will 
be released next week.

Have fun kids. 




-----Original Message-----
From: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]On Behalf Of Patrick Beart
Sent: Wednesday, August 30, 2000 4:45 PM
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: [cobalt-users] Re: [Raq3] File permissions- rejected from admin


At 4:57 PM -0400 8/30/00, Joe Kerns wrote:
>  > So if you can't FTP Chmod after the update. Your going to spend
>>  hours telnetting in to any site just to chmod directories and scripts.
>>  my 10cents, Lennie
>
>That's not even worth $.02. While it may be somewhat of a burden to 
>open some sort of shell session, why does it take hours? That makes 
>0 (zero) sense...it's 1 small line of text to type...

	Well, let's see:

	1 small line to type
	x (times) the number of files in each (cgi-bin)directory
	x  the number of directories/account on the server
	x  the number of times that each user/client needs updates to 
such files
	=  lots of wasted time, that might not be billable.

	Right now, "site administrators" can make their own changes, 
via FTP. (or they COULD before the last update was installed, 
anyway.) Now, they have to call ME to make the changes. As much as it 
only takes about 20 seconds to type in the command, I have to quit 
what I'm already doing, then it takes about 5 minutes to open a 
Telnet session (assuming that I'm already connected to the 'Net), 
navigate to the correct directory, make the change, verify the 
change, and close out the session. Then confirm with the client.
	My clients assume that such problems fall under the heading 
of "Customer service" and are therefore not billable. That means that 
it cost me far more in MONEY, than in TIME, than it did before!

	Since you asked....          ; )



Patrick Beart
-- 
-------------------------------------------------------------------
patrick@xxxxxxxxxxxxxxxxxxx       503-558-8322      Clackamas(Portland), OR
Web Architecture:   http://www.WebArchitecture.com
Intelligent Internet consulting, site development, and hosting 
solutions since 1994

iWeb4Biz: Internet hosting for businesses   http://www.iWeb4Biz.com/
  -------------------------------------------------------------------


_______________________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To Subscribe or Unsubscribe, please go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users