on a system I recently was asked to administer, the following was seen :

drwxr-xrwx 7 root root 4.0K Oct 9 19:16 cgi-bin/
drwxr-xr-x 5 root root 4.0K Aug 25 22:53 htdig/
drwxr-xr-x 14 root root 4.0K Sep 13 16:09 htdocs/

note the cgi-bin permissions. under htdocs there is the rootdir of the
pages displayed.

I have been told that this rwx was necessary to be able to have
awstats's webpage update function to work. I checked the docs and that
indeed says that you need rwx access.

however, is this secure ? I tend not to like this kind of access to such
a directory. anyone else who can share some thoughts ?


