[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] All folders visable on whole server
- Subject: RE: [cobalt-users] All folders visable on whole server
- From: "Dee Dreslough" <dee@xxxxxxxxxxx>
- Date: Fri Dec 8 18:09:12 2000
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
> Forgot to add to my last message:
>
> <Files ~ "^adminpro\.(cgi|pl)$">
> Order allow,deny
> Deny from all
> </Files>
>
> Test: http://www.ctusa.net/cgi-bin/adminpro.cgi
Hi!
Could someone just rename the script something like 'notadminpro.cgi' and
still run it? Is there a way we could sniff out the contents of the file or
something, or check for the ID of the person who is using the program and
only give them access to their directories...?
Thank you for this security clue, btw!
-Dee Dreslough
(Raq newbie... :) )