Re: WebCatalog security on NT
This WebDNA talk-list message is from 2000
It keeps the original formatting.
numero = 27184
interpreted = N
texte = > >Hi,> >> >I would like to suggest a customer to offer webcat, on their NT web> >hosting systems.> >> >I have seen some posts from Ken, and I know that is the case on a> >Mac, that somebody with upload capabilities, could possibly cause *a> >lot* of trouble, deleting files, running applescripts, messing with> >the TCPSend command, and so on> >> >The customer offers web hosting services, with virtual domains, on >an NT box.> >> >Can webcat be told to run only in certain folders?>>No, that's the major problem preventing it from being a secure >hosting tool. Webcat on NT can run DOS commands/scripts, so nothing >is safe on NT, just like nothing is safe on Macintosh. Even without >AppleScript/DOS contexts, webcat's ability to navigate the folder >hierarchy with its standard features puts other sites in danger of >being hacked quite easily.Thanks Ken,That was a pretty fast response...So I assume that since people *do* host sites on NT, they still must have devised a method of doing that... What are the prevention steps that could be taken do have a somewhat secure hosting.The same hosting box runs ColdFusion, Could ColdFusion navigate folder hierarchy, like webcat? Because if that's the case, I could suggest disabling the DOS commands, and then it would be posing the same risk as CF.Serban-------------------------------------------------------------Brought to you by CommuniGate Pro - The Buzz Word Compliant Messaging Server.To end your Mail problems go to
.This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to
Associated Messages, from the most recent to the oldest:
> >Hi,> >> >I would like to suggest a customer to offer webcat, on their NT web> >hosting systems.> >> >I have seen some posts from Ken, and I know that is the case on a> >Mac, that somebody with upload capabilities, could possibly cause *a> >lot* of trouble, deleting files, running applescripts, messing with> >the TCPSend command, and so on> >> >The customer offers web hosting services, with virtual domains, on >an NT box.> >> >Can webcat be told to run only in certain folders?>>No, that's the major problem preventing it from being a secure >hosting tool. Webcat on NT can run DOS commands/scripts, so nothing >is safe on NT, just like nothing is safe on Macintosh. Even without >AppleScript/DOS contexts, webcat's ability to navigate the folder >hierarchy with its standard features puts other sites in danger of >being hacked quite easily.Thanks Ken,That was a pretty fast response...So I assume that since people *do* host sites on NT, they still must have devised a method of doing that... What are the prevention steps that could be taken do have a somewhat secure hosting.The same hosting box runs ColdFusion, Could ColdFusion navigate folder hierarchy, like webcat? Because if that's the case, I could suggest disabling the DOS commands, and then it would be posing the same risk as CF.Serban-------------------------------------------------------------Brought to you by CommuniGate Pro - The Buzz Word Compliant Messaging Server.To end your Mail problems go to .This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to
Serban Constantinescu
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Prevent multiple appends with Reload Button (1997)
[WebDNA] [BULK] WebDNA 6.2 or 7.x Hosting (might be) Needed (2011)
subtotal (2000)
RE: Webcatalog and CyberSTUD (1998)
ConvertChars? (1998)
Math Problem - Format? (1997)
Major Security Hole (1998)
MacOS X upgrade pricing plan (1999)
OT: Limit on # of Pulldown entries (1997)
Locking up with WebCatalog... (1997)
Web Catalog 2 demo (1997)
Blocking off access (2005)
Bug Report, maybe (1997)
IP Address (2001)
Summing fields (1997)
Editing the search string (1997)
Bug or syntax error on my part? (1997)
Methods of protecting "invoice page" (2003)
Not really WebCat- (1997)
Sorting error (1997)