[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] Problem with cgi
- Subject: Re: [cobalt-users] Problem with cgi
- From: "E.B. Dreger" <eddy+public+spam@xxxxxxxxxxxxxxxxx>
- Date: Sat Mar 9 22:35:01 2002
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
> Date: Sun, 10 Mar 2002 10:14:21 -0000
> From: Utopia Research Dept <research@xxxxxxxxxxxxx>
> Help !!
> We have raq 2 , 3 and 4 's and would like to put some cgi
> scripts "BELOW" the document root for security purposes .
> We realize that we can run cgi's from anywhere because of the
> cgi wrapper but we need to hide some scripts but still be able
No, you can run CGI scripts anywhere because the config files
specify that as okay. The wrapper is to ensure that CGI scripts
execute as the proper user.
> to run them .
Security by obscurity isn't much security. If you want to
protect scripts, put them in their own directory with HTTP auth
required.
> Has anybody managed to do this with the raqs ?
> Help would be much appreciated !!!
Read
http://httpd.apache.org/docs/mod/mod_cgi.html
first.
Eddy
Brotsman & Dreger, Inc. - EverQuick Internet Division
Phone: +1 (316) 794-8922 Wichita/(Inter)national
Phone: +1 (785) 865-5885 Lawrence
--
Date: Mon, 21 May 2001 11:23:58 +0000 (GMT)
From: A Trap <blacklist@xxxxxxxxx>
To: blacklist@xxxxxxxxx
Subject: Please ignore this portion of my mail signature.
These last few lines are a trap for address-harvesting spambots. Do NOT
send mail to <blacklist@xxxxxxxxx>, or you are likely to be blocked.