Re: CGI security on a shared web server
From: Kurt Seifried (bugtraq@seifried.org)Date: 05/23/02
- Previous message: George Dinwiddie: "CGI security on a shared web server"
- In reply to: George Dinwiddie: "CGI security on a shared web server"
- Next in thread: Steffen Dettmer: "Re: CGI security on a shared web server"
- Next in thread: Antonomasia: "Re: CGI security on a shared web server"
- Reply: Steffen Dettmer: "Re: CGI security on a shared web server"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Kurt Seifried" <bugtraq@seifried.org> To: "George Dinwiddie" <gdinwiddie@min.net>, <secprog@securityfocus.com> Date: Thu, 23 May 2002 14:05:36 -0600
One possible solution, assuming you need to write the data but not read it
until later is to encrypt it, generate a public/private keypair using
pgp/gnupg, load the public key onto the server with your app, have it write
the files after encrypting the data. Thus you can retrieve the data (ftp,
www, whatever) and then decrypt it at your leisure and use it.
Kurt Seifried, kurt@seifried.org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://seifried.org/security/
http://www.iDefense.com/
- Previous message: George Dinwiddie: "CGI security on a shared web server"
- In reply to: George Dinwiddie: "CGI security on a shared web server"
- Next in thread: Steffen Dettmer: "Re: CGI security on a shared web server"
- Next in thread: Antonomasia: "Re: CGI security on a shared web server"
- Reply: Steffen Dettmer: "Re: CGI security on a shared web server"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|