[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Raq4r Backup



> Hi Carrie,
> You have made good contribution.
> The script can be improved further.

Oh! He cc'd this to me, didn't know he'd sent it to the list too.

> You have mentioned that you are placing the home.tar
> in your anonymous ftp directory.

Actually I don't do that with the version of the script that I am using. I
don't even have anonymous ftp enabled on my site.
But I don't want to go advertising to everyone where I *do* drop my tar
file... *smile*
That's one of the reasons I said to modify it to drop it somewhere else.

> My question is what happens if any anonymous user pulls out
> home.tar from your anonymous ftp site?

That would be very, very bad.

> Did you realize the danger, that anonymous user will
> have all your clients cgi programs, personal and privacy data?
> In other words, you server is left *open* to all.

Yep, I realized this - again, that's why I drop mine somewhere else.  ;)

So let me amend my letter, since I suppose I was *too* subtle...
MODIFY THE SCRIPT SO IT DROPS THE TAR FILE SOMEWHERE ELSE!

I'm trying to base everything I write on the assumption that script kiddies
are reading each and every post.  I've been trying to be as vague as
possible while still giving a specific answer. I don't suppose it's working.
I've never been one for subtlety - Scorpio to the bone.  <grin>

CarrieB