[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] RISKY BUSINESS



> You know, I see poor souls getting hacked in here all the time. It's
almost
> like they're missing the ugly simple truth:
>
> If you don't want your users running malicious scripts, do not allow cgi
> access and keep ftp uploads to admin's only. Allow no anonymous access.

Although no anonymous access is something I subscribe to - what use is a
webhost that doesn't allow its users to upload files? If a user can't upload
files, how do they get their HTML online? If you don't allow cgi access,
what extra do you offer over Tripod etc. who don't charge for their
services?

There are always tradeoffs involved in running a server where you allow
other people access. When you price your service, you have to add something
in there to cover the costs of a malicious user. From the number of
successful webhosting companies out there, the tradeoff with allowing users
to upload their own files and have cgi access is acceptable to most
(fortunately!)