[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] All folders visable on whole server



> Forgot to add to my last message:
>
> <Files ~ "^adminpro\.(cgi|pl)$">
>     Order allow,deny
>     Deny from all
> </Files>
>
> Test: http://www.ctusa.net/cgi-bin/adminpro.cgi

Hi!

Could someone just rename the script something like 'notadminpro.cgi' and
still run it?  Is there a way we could sniff out the contents of the file or
something, or check for the ID of the person who is using the program and
only give them access to their directories...?

Thank you for this security clue, btw!

-Dee Dreslough
(Raq newbie... :) )