<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.swcp.com/w/index.php?action=history&amp;feed=atom&amp;title=KB_118</id>
	<title>KB 118 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.swcp.com/w/index.php?action=history&amp;feed=atom&amp;title=KB_118"/>
	<link rel="alternate" type="text/html" href="https://wiki.swcp.com/w/index.php?title=KB_118&amp;action=history"/>
	<updated>2026-10-06T22:38:51Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://wiki.swcp.com/w/index.php?title=KB_118&amp;diff=218&amp;oldid=prev</id>
		<title>Jamii at 17:52, 4 June 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.swcp.com/w/index.php?title=KB_118&amp;diff=218&amp;oldid=prev"/>
		<updated>2008-06-04T17:52:15Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:52, 4 June 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===How can I protect my CGI-scripts on my website from being accessed by&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===How can I protect my CGI-scripts on my website from being accessed by just anyone?===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;just anyone?===&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Article:118&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Article:118&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Created:2001-05-25 16:41:32&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Created:2001-05-25 16:41:32&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Jamii</name></author>
	</entry>
	<entry>
		<id>https://wiki.swcp.com/w/index.php?title=KB_118&amp;diff=217&amp;oldid=prev</id>
		<title>Jamii: New page: ===How can I protect my CGI-scripts on my website from being accessed by just anyone?===  Article:118  Created:2001-05-25 16:41:32  Categories:    Web Publishing  ====Question or Symptom==...</title>
		<link rel="alternate" type="text/html" href="https://wiki.swcp.com/w/index.php?title=KB_118&amp;diff=217&amp;oldid=prev"/>
		<updated>2008-06-04T17:51:30Z</updated>

		<summary type="html">&lt;p&gt;New page: ===How can I protect my CGI-scripts on my website from being accessed by just anyone?===  Article:118  Created:2001-05-25 16:41:32  Categories:    Web Publishing  ====Question or Symptom==...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;===How can I protect my CGI-scripts on my website from being accessed by&lt;br /&gt;
just anyone?===&lt;br /&gt;
 Article:118&lt;br /&gt;
 Created:2001-05-25 16:41:32&lt;br /&gt;
 Categories:&lt;br /&gt;
   Web Publishing&lt;br /&gt;
&lt;br /&gt;
====Question or Symptom====&lt;br /&gt;
htaccess protects your HTML files on your website from being accessed by&lt;br /&gt;
anyone. It would make sense that you could use the same process to&lt;br /&gt;
protect your CGI-scripts, however it will not stop a user from running a&lt;br /&gt;
script on your website. CGI-wrap is the program that we use to have&lt;br /&gt;
those files run as the owner of the website. If we did not do that, then&lt;br /&gt;
the pages would have to be run as &amp;#039;nobody.&amp;#039; What are the options that&lt;br /&gt;
one has to protect those pages dynamically produced from being accessed&lt;br /&gt;
by unauthorized people?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Resolution====&lt;br /&gt;
 The ways that you can fix the problem are:&lt;br /&gt;
  &lt;br /&gt;
 1. If the scripts are your own, and the code can be altered, what you&lt;br /&gt;
 could do is rewrite them so that at the beginning of the session you have&lt;br /&gt;
 the user authenticate through the script.  Once the user authenticates, the &lt;br /&gt;
 script leaves a cookie on the user&amp;#039;s computer. The cookie can either expire &lt;br /&gt;
 after a certain amount of time, or become obsolete once the transaction is done.&lt;br /&gt;
 Each time one of the scripts are accessed, they check to see if there is a&lt;br /&gt;
 proper cookie.&lt;br /&gt;
 &lt;br /&gt;
  When a user returns to a bookmarked URL the cookie will have expired&lt;br /&gt;
  and the page will produce an error message. This can contain a link to&lt;br /&gt;
  the &amp;quot;top&amp;quot; of the site for authentication.&lt;br /&gt;
 &lt;br /&gt;
  This can be done by one script that is included in your other scripts.&lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
 2. Instead of using &amp;#039;GET&amp;#039; statements to pass arguments to the CGI scripts, use&lt;br /&gt;
 &amp;#039;POST&amp;#039; and so nothing is passed in the URL.  Bookmarks are saved URLs, and&lt;br /&gt;
 if you are passing arguments through the URL to the scripts, people will&lt;br /&gt;
 be able to bookmark that.&lt;br /&gt;
  &lt;br /&gt;
 You&amp;#039;ll need to make sure that when the script is run with no arguments&lt;br /&gt;
 it&amp;#039;s produces an appropriate error message.&lt;br /&gt;
 &lt;br /&gt;
  &lt;br /&gt;
 3. If we turned off CGI-wrap so that you could protect those&lt;br /&gt;
 scripted pages with htaccess, however, then the scripts cannot run&lt;br /&gt;
 under your UID but under &amp;#039;nobody.&amp;#039; That means that all files that are&lt;br /&gt;
 written by the scripts are world readable meaning they could possibly be &lt;br /&gt;
 read by anyone. &lt;br /&gt;
  &lt;br /&gt;
 For example, if you secure a directory so that it is not world&lt;br /&gt;
 readable, but you save a file in there that is world readable &lt;br /&gt;
 and writable, then that file can still be read or written&lt;br /&gt;
 over if someone happens to know that it&amp;#039;s there.&lt;br /&gt;
 &lt;br /&gt;
 Also these files will be difficult for you to manage as they won&amp;#039;t be&lt;br /&gt;
 owned by you.&lt;/div&gt;</summary>
		<author><name>Jamii</name></author>
	</entry>
</feed>