Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 09 Sep 2000 19:27:40 +0400
From:      "Simakin Alexandr" <simakin@inbox.ru>
To:        freebsd-questions@FreeBSD.ORG
Subject:   CGI-scripts security
Message-ID:  <E13XmXc-000Ljj-00@hearst.mail.ru>

next in thread | raw e-mail | index | archive | help
Does anybody knows, how to allow read/write access 
for users cgi-scripts ONLY in users own home directories
and restrict all access (including read!) to all other directories
and its content.

CGIWrap is cool, but if you have such files:
-rw-r--r--  1 root  wheel   1067 Sep  9 17:28 /etc/passwd
you can read this file even when CGIWrap installed, 
find users with SU rights, lunch password finder utility 
and so on.

Alex Simakin


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?E13XmXc-000Ljj-00>