Re: Policing user CGI scripts

chris_at_nospam.com
Date: 07/05/04

  • Next message: Bodo Eggert: "Re: Policing user CGI scripts"
    Date: Sun, 04 Jul 2004 22:43:44 GMT
    
    

    On Sun, 4 Jul 2004 17:20:47 +0000 (UTC), Akop Pogosian
    <akopps+usenet@ocf.berkeley.edu.remuvthis.com> wrote:

    >Does there exist a security tool that can be used to scan the user
    >home directories for presence of the versions of popular, freely
    >distributed CGI or .php scripts that have well known security
    >problems? Of course, if such tool could also look for the dangerous
    >code in general that would be even better.
    >
    >
    >-akop

    While looking for known vulnerable cgi-scripts is a good idea, it's
    not a complete solution. How do you handle poorly written scripts
    created by users?

    Best bet is to limit the environment and control what damage any
    errant script can do. As another posted stated, proper firewall
    controls are a good idea. Setting up the webserver to run cgi-scripts
    as a safe user is vital. I know at least one provider that runs all
    cgi-scripts under a single account which allows scripts to see other
    users files (horrible idea).

    -Chris


  • Next message: Bodo Eggert: "Re: Policing user CGI scripts"

    Relevant Pages

    • Re: Policing user CGI scripts
      ... >distributed CGI or .php scripts that have well known security ... While looking for known vulnerable cgi-scripts is a good idea, ... How do you handle poorly written scripts ... Best bet is to limit the environment and control what damage any ...
      (comp.security.misc)
    • Re: Perl CGI scripts unable to open TCP sockets -- permission denied
      ... All of my scripts run from the prompt. ... None of my scripts involving sockets run as cgi-scripts. ... My cgi scripts are running as "apache". ...
      (comp.infosystems.www.authoring.cgi)
    • Re: browser output
      ... > I use the following in all my scripts: ... Don't 'exit' from CGI-scripts. ... IMO, don't 'exit' from any scripts; ... "The trouble with programmers is that you can never tell what a programmer is doing until it's too late." ...
      (comp.lang.perl.misc)
    • Re: Secure shared web hosting using MAC Framework
      ... run the web server and web users shell in a jail, ... Those rights should have priority on any traditional unix file ... This directive allows you to disable certain functions for security reasons. ... Web users and executed web scripts shouldn't be able to read ...
      (FreeBSD-Security)
    • RE: Techniques for Vulneability discovery
      ... "Art & Science of Computer Security" to be published ... to run scripts and nmap (swell..$2-4k to learn this ... hint hint, E&Y, hint hint.. ... How do experts discover vulnerabilities in a ...
      (Vuln-Dev)