RE: Writefile outside WebSTAR hierarchy?

This WebDNA talk-list message is from

1997


It keeps the original formatting.
numero = 13273
interpreted = N
texte = At 03:44 PM 9/2/97, you wrote: >Ken - > >>Can writefile create files anywhere on the hard drive, or are these >>files restricted to the webstar hierarchy? > >It can create files anywhere, which is useful if you store all your log files in a folder outside the WebSTAR hierarchy, for instance. Because this is only available as a context, you as administrator are the only one who can create files with [writefile]. > >However, this brings up a potential security concern - you need to be careful about who is allowed to upload WebCatalog template files to your server, as the [writefile] context can both create files and overwrite existing files. This is a concern whether [writefile] is limited to the WebSTAR hierarchy or not. If you are allowing others to upload webcatalog files, keep this in mind and limit access to users you can trust (and always keep regular backups, whether it's for security or not! ;) ) > >I hope this is clear, > >Marc Eagle >StarNine Technologies >http://www.smithmicro.com/ > Marc,Does this apply to Windows NT servers as well? Can [writefile] create or overwrite files outside of the webroot of the server? According to our systems engineer, if you can do this, the [writefile] would be generating files with the equivalent of administrator access. Not nice for security......................................................................... W O R L D P O I N T I N T E R A C T I V E DANIEL CAMERON web engineer Honolulu San Francisco 2800 woodlawn drive 222 sutter street dcameron@worldpoint.com suite 170 sixth floor www.worldpoint.com honolulu, hi 96822 san francisco, ca 94108 voice.808.539.3932 fax.808.539.3943 page.808.598.8640 ..................................................................... Associated Messages, from the most recent to the oldest:

    
  1. RE: Writefile outside WebSTAR hierarchy? (Marc Eagle 1997)
  2. RE: Writefile outside WebSTAR hierarchy? (Daniel Cameron 1997)
At 03:44 PM 9/2/97, you wrote: >Ken - > >>Can writefile create files anywhere on the hard drive, or are these >>files restricted to the webstar hierarchy? > >It can create files anywhere, which is useful if you store all your log files in a folder outside the WebSTAR hierarchy, for instance. Because this is only available as a context, you as administrator are the only one who can create files with [writefile]. > >However, this brings up a potential security concern - you need to be careful about who is allowed to upload WebCatalog template files to your server, as the [writefile] context can both create files and overwrite existing files. This is a concern whether [writefile] is limited to the WebSTAR hierarchy or not. If you are allowing others to upload webcatalog files, keep this in mind and limit access to users you can trust (and always keep regular backups, whether it's for security or not! ;) ) > >I hope this is clear, > >Marc Eagle >StarNine Technologies >http://www.smithmicro.com/ > Marc,Does this apply to Windows NT servers as well? Can [writefile] create or overwrite files outside of the webroot of the server? According to our systems engineer, if you can do this, the [writefile] would be generating files with the equivalent of administrator access. Not nice for security......................................................................... W O R L D P O I N T I N T E R A C T I V E DANIEL CAMERON web engineer Honolulu San Francisco 2800 woodlawn drive 222 sutter street dcameron@worldpoint.com suite 170 sixth floor www.worldpoint.com honolulu, hi 96822 san francisco, ca 94108 voice.808.539.3932 fax.808.539.3943 page.808.598.8640 ..................................................................... Daniel Cameron

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

Wanted: More Math Functions (or, Can You Solve This?) (1997) apostrophe in search item (1997) too many nested tags ... (1997) all records returned. (1997) RAM to disk (2002) Newbie problem blah blah blah (1997) [convertchars] limits (1998) Using Plug-In while running 1.6.1 (1997) It just Does't add up!!! (1997) mac hack (1997) WebCat2 - [include] tags (1997) Date stamp and purging (1998) Another bug to squash (WebCat2b13 Mac .acgi) (1997) Summing fields (1997) HTTP header line is too long? (1997) HELP WITH DATES (1997) What is WebDNA (1997) PCS Frames (1997) Robert Minor duplicate mail (1997) WebCommerce: Folder organization ? (1997)