KB 118: Difference between revisions
From SWCP Support Wiki
Jump to navigationJump to search
New page: ===How can I protect my CGI-scripts on my website from being accessed by just anyone?=== Article:118 Created:2001-05-25 16:41:32 Categories: Web Publishing ====Question or Symptom==... |
No edit summary |
||
| Line 1: | Line 1: | ||
===How can I protect my CGI-scripts on my website from being accessed by | ===How can I protect my CGI-scripts on my website from being accessed by just anyone?=== | ||
just anyone?=== | |||
Article:118 | Article:118 | ||
Created:2001-05-25 16:41:32 | Created:2001-05-25 16:41:32 | ||
Latest revision as of 11:52, 4 June 2008
How can I protect my CGI-scripts on my website from being accessed by just anyone?
Article:118 Created:2001-05-25 16:41:32 Categories: Web Publishing
Question or Symptom
htaccess protects your HTML files on your website from being accessed by anyone. It would make sense that you could use the same process to protect your CGI-scripts, however it will not stop a user from running a script on your website. CGI-wrap is the program that we use to have those files run as the owner of the website. If we did not do that, then the pages would have to be run as 'nobody.' What are the options that one has to protect those pages dynamically produced from being accessed by unauthorized people?
Resolution
The ways that you can fix the problem are: 1. If the scripts are your own, and the code can be altered, what you could do is rewrite them so that at the beginning of the session you have the user authenticate through the script. Once the user authenticates, the script leaves a cookie on the user's computer. The cookie can either expire after a certain amount of time, or become obsolete once the transaction is done. Each time one of the scripts are accessed, they check to see if there is a proper cookie. When a user returns to a bookmarked URL the cookie will have expired and the page will produce an error message. This can contain a link to the "top" of the site for authentication. This can be done by one script that is included in your other scripts.
2. Instead of using 'GET' statements to pass arguments to the CGI scripts, use 'POST' and so nothing is passed in the URL. Bookmarks are saved URLs, and if you are passing arguments through the URL to the scripts, people will be able to bookmark that. You'll need to make sure that when the script is run with no arguments it's produces an appropriate error message. 3. If we turned off CGI-wrap so that you could protect those scripted pages with htaccess, however, then the scripts cannot run under your UID but under 'nobody.' That means that all files that are written by the scripts are world readable meaning they could possibly be read by anyone. For example, if you secure a directory so that it is not world readable, but you save a file in there that is world readable and writable, then that file can still be read or written over if someone happens to know that it's there. Also these files will be difficult for you to manage as they won't be owned by you.