From: Ben Giddings Date: 2003-07-29T02:03:07+09:00 Subject: [OT] CGI security [Was Re: install questions] On Mon July 28 2003 12:28 pm, Hal E. Fulton wrote: > But regardless of where the data is stored: What about CGIs whose > inherent function is recording data from the user? E.g. a guestbook? > It has to write that stuff somewhere. Surely a database is overkill > in many circumstances. In that case, maybe. If you hard-code the filename you're writing to, don't do any evals, and do some checks on what you're writing to the file, that should be ok. Even then, however, you should be careful someone can't write arbitrary javascript code into the guestbook. It wouldn't affect the web server, but it would affect anybody reading the guestbook entries. And, as to writing to things under cgi-bin, the danger there is that the web server assumes things there are files meant to be executed and not files whose contents are meant to be sent out over the web. 99% of the times, this will just mean an error if someone tries to access /cgi-bin/guestbook.txt. On the other hand, if the file is created accidentally as executable, and happens to start off empty, someone could write something like "#!/bin/sh\ncat /etc/passwd" into the guestbook. The other issue is bugs in the language. Who knows if there's some undiscovered bug in the Ruby code or in one of the libraries your program requires. Since a CGI is basically a program on your server that anybody in the world is allowed to run, it's best to be overly cautious about what might happen. That's why (getting back to the original point) I think it's better if you install CGIs simply by copying them to the right directory and maybe making them executable. Anything more than that I think is unnecessary. Ben