Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Categories

Security Question on a CGI script.[please answer]

grekopgrekop Member Posts: 3
I have created a perl script(mailing list) that keeps the emails into a text database file. If a cracker finds this file he will open it and he will get all the emails. I want to have read/write permissions on the file for the scipt but I don't want the file to be viewable by someone else.I can encode it by I need it to be in plain text.

Thank you.
CUL8R

Comments

  • jcarlssonjcarlsson Member Posts: 21
    : I have created a perl script(mailing list) that keeps the emails into a text database file. If a cracker finds this file he will open it and he will get all the emails. I want to have read/write permissions on the file for the scipt but I don't want the file to be viewable by someone else.I can encode it by I need it to be in plain text.

    When you run it as a CGI on apache it is run by nobody (a user with almost the same permissions as root but nobody has no shell) so what you can do is place nobody as owner of that file and chmod it so that only the owner can read and write to it. Then you will only be able to access it from the script or if you are root.

    [red]--[/red]
    [green]jcarlsson[/green] [blue]<[/blue][purple]jcarlsson@linux.nu[/purple][blue]>[/blue]
    [red]http://www.jcarlsson.tk[/red]

  • Justin BibJustin Bib USAMember Posts: 0

    ___ // http://forcoder.org // free video tutorials and ebooks about // Go, MATLAB, PHP, C#, Visual Basic, JavaScript, C, Visual Basic .NET, Objective-C, C++, Java, R, PL/SQL, Swift, Perl, Ruby, Assembly, Scratch, Python, Delphi Rust, COBOL, Lisp, Kotlin, F#, Logo, FoxPro, Julia, SAS, LabVIEW, Prolog, Alice, Awk, Scheme, Ada, Clojure, Dart, Erlang, VBScript, D, Bash, Lua, ML, Fortran, Transact-SQL, Apex, Hack, ABAP, Crystal, Scala // __________

Sign In or Register to comment.