Anyone can access accounting page

Date: Wed, 28 Oct 1998 00:23:48 -0800
From: John Nemeth <jnemeth@cue.bc.ca>
To: Gord Fisch <gfisch@gpfn.sk.ca>, techteam@neale.gpfn.sk.ca
Cc: csuite-dev@chebucto.ns.ca
Precedence: bulk
Return-Path: <csuite-dev-mml-owner@chebucto.ns.ca>

next message in archive
no next message in thread
previous message in archive
previous message in thread
Index of Subjects

Index of Subjects
On Oct 22, 12:24am, Gord Fisch wrote:
} 
} Had a troubling e-mail from Gord Hines. He was searching for United Way in
} Regina and found it but also this URL
} http://www.gpfn.sk.ca/cgi-officebin/reverse-money 
} 
} Anyone could go in a dick with the accounting files. Also wide open were
} scripts in cgi-membin, cgi-cnbin and cgi-ipbin.

     My system doesn't have this problem.

} How this got on any search engine is a mystery. Anyway, I added a few
} lines to /etc/apache/access.conf for these directories.

     This is not where CSuite stores its Apache configuration file.
If you replace Apache, or otherwise muck with its configuration, then
it is your responsibility to make sure that you don't break anything.
Also, when sending in a bug report, you should mention any pertinent
changes that you have made to CSuite, so that people don't waste their
time looking for non-existant bugs.

} This generated errors. It took me a while to realize the .htaccess files
} had 
} AuthName Office Administration
} which had to be quoted
} AuthName "Office Administration" 
} Now they work.

     Although, it is technically wrong, older versions of Apache did
accept it without the quotes.

}-- End of excerpt from Gord Fisch

next message in archive
no next message in thread
previous message in archive
previous message in thread
Index of Subjects