[lug] preventing malicious scripts

charles at lunarmedia.net charles at lunarmedia.net
Thu Sep 6 18:58:52 MDT 2001


is there a method to set a directory as a able to execute cgi scripts,
however limit which scripts within the directory are executable?

i thought about the possibility of limiting it based on name, however i
would assume the crafty client would simply upload a malicious script with
the name of the accepted script and still be able to gather the info i am
trying to prevent them from retrieving.

any ideas on how to let clients have access but still be able to sleep at
night?

thanks -charles




More information about the LUG mailing list