Re: [GENERAL] cgi with postgres

Поиск
Список
Период
Сортировка
От The Hermit Hacker
Тема Re: [GENERAL] cgi with postgres
Дата
Msg-id Pine.BSF.4.21.0001142014370.46499-100000@thelab.hub.org
обсуждение исходный текст
Ответ на cgi with postgres  (Jeff MacDonald <jeff@hub.org>)
Ответы Re: [GENERAL] cgi with postgres  (Peter Eisentraut <peter_e@gmx.net>)
Список pgsql-general
On Fri, 14 Jan 2000, Jeff MacDonald wrote:

> hey folks,
>
> this is a security issue i'd like to get some info
> on, i'm sure it's more with cgi than postgres, but
> heck.
>
> issue: how to secure cgi's that access postgres
>
> problem: passwords for postgres database are stored
>       in plain text in scripts. (lets assume, perl,
>       not a compiled language)
>
> points:
>     make cgi dir 711
>     big deal, they can get the name of the file
>     from the web, and copy it.
>
>     set an obscure cgi script alias in apache
>     big deal, they can read the cgi conf file.

Side point ... why isn't the apache conf file secure?  Only user root
needs to be able to read it, no?

Marc G. Fournier                   ICQ#7615664               IRC Nick: Scrappy
Systems Administrator @ hub.org
primary: scrappy@hub.org           secondary: scrappy@{freebsd|postgresql}.org


В списке pgsql-general по дате отправления:

Предыдущее
От: Kevin Heflin
Дата:
Сообщение: problem with date range
Следующее
От: "Neil Burrows"
Дата:
Сообщение: More Rule creation problems (and nowhere near 8K)