Anyone can access accounting page

Date: Thu, 22 Oct 1998 00:24:40 -0600 (CST)
From: Gord Fisch <gfisch@gpfn.sk.ca>
To: techteam@neale.gpfn.sk.ca
cc: csuite-dev@chebucto.ns.ca
Precedence: bulk
Return-Path: <csuite-dev-mml-owner@chebucto.ns.ca>

next message in archive
next message in thread
previous message in archive
Index of Subjects


Greetings,

Had a troubling e-mail from Gord Hines. He was searching for United Way in
Regina and found it but also this URL
http://www.gpfn.sk.ca/cgi-officebin/reverse-money 

Anyone could go in a dick with the accounting files. Also wide open were
scripts in cgi-membin, cgi-cnbin and cgi-ipbin.

How this got on any search engine is a mystery. Anyway, I added a few
lines to /etc/apache/access.conf for these directories.
This generated errors. It took me a while to realize the .htaccess files
had 
AuthName Office Administration
which had to be quoted
AuthName "Office Administration" 
Now they work.

Maybe no one at csuite has had anyone try to access the script directly?


Gord	|| Program Officer: SK Cultural Exchange Society 
Fisch	|| Webmaster: Great Plains Free-Net

next message in archive
next message in thread
previous message in archive
Index of Subjects