landon: HIGH: bookmark file

From: James Fifield <fifield@ug.cs.dal.ca>
To: csuite-tech@chebucto.ns.ca
Date: Mon, 26 May 1997 09:02:09 -0300
Precedence: bulk

next message in archive
next message in thread
previous message in archive
Index of Subjects


Through the settings page, I can set my bookmark file to be anything I choose.

If I log out, and then log back in, I can then read that bookmark file, 
(although I'm not yet sure if I'm able to write to it, it doesn't seem so).

However, the point is that I am able to read any file in at least my home 
directory.

Fortunately, this will not allow certain key files to be compromised it seems, 
for instance, $CS_ROOT/etc/htpasswd still seems to be unreadable, (i'm not sure 
why), but that's a "GoodThing(tm)".

Still, it's something to look at, perhaps we could "fix" the bookmark file 
temporarily?

--
James Fifield
<fifield@ug.cs.dal.ca>


next message in archive
next message in thread
previous message in archive
Index of Subjects