KB 118: Difference between revisions

From SWCP Support Wiki
Jump to navigationJump to search
New page: ===How can I protect my CGI-scripts on my website from being accessed by just anyone?=== Article:118 Created:2001-05-25 16:41:32 Categories: Web Publishing ====Question or Symptom==...
 
No edit summary
 
Line 1: Line 1:
===How can I protect my CGI-scripts on my website from being accessed by
===How can I protect my CGI-scripts on my website from being accessed by just anyone?===
just anyone?===
  Article:118
  Article:118
  Created:2001-05-25 16:41:32
  Created:2001-05-25 16:41:32

Latest revision as of 11:52, 4 June 2008

How can I protect my CGI-scripts on my website from being accessed by just anyone?

Article:118
Created:2001-05-25 16:41:32
Categories:
  Web Publishing

Question or Symptom

htaccess protects your HTML files on your website from being accessed by anyone. It would make sense that you could use the same process to protect your CGI-scripts, however it will not stop a user from running a script on your website. CGI-wrap is the program that we use to have those files run as the owner of the website. If we did not do that, then the pages would have to be run as 'nobody.' What are the options that one has to protect those pages dynamically produced from being accessed by unauthorized people?


Resolution

The ways that you can fix the problem are:
 
1. If the scripts are your own, and the code can be altered, what you
could do is rewrite them so that at the beginning of the session you have
the user authenticate through the script.  Once the user authenticates, the 
script leaves a cookie on the user's computer. The cookie can either expire 
after a certain amount of time, or become obsolete once the transaction is done.
Each time one of the scripts are accessed, they check to see if there is a
proper cookie.

 When a user returns to a bookmarked URL the cookie will have expired
 and the page will produce an error message. This can contain a link to
 the "top" of the site for authentication.

 This can be done by one script that is included in your other scripts.
 
2. Instead of using 'GET' statements to pass arguments to the CGI scripts, use
'POST' and so nothing is passed in the URL.  Bookmarks are saved URLs, and
if you are passing arguments through the URL to the scripts, people will
be able to bookmark that.
 
You'll need to make sure that when the script is run with no arguments
it's produces an appropriate error message.

 
3. If we turned off CGI-wrap so that you could protect those
scripted pages with htaccess, however, then the scripts cannot run
under your UID but under 'nobody.' That means that all files that are
written by the scripts are world readable meaning they could possibly be 
read by anyone. 
 
For example, if you secure a directory so that it is not world
readable, but you save a file in there that is world readable 
and writable, then that file can still be read or written
over if someone happens to know that it's there.

Also these files will be difficult for you to manage as they won't be
owned by you.