<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1001175" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1001175</link>
    <description></description>
    <language>en</language>
          <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/looking-absolute-beginners-guide-cgi-security#comment-1005123</link>
    <description> &lt;p&gt;Orpheus,&lt;/p&gt;
&lt;p&gt;Thank You for your reply.&lt;/p&gt;
&lt;p&gt;This would be for those who can chmod a file. There are a lot of &quot;webmasters&quot; who have learned enough about CGI to find what they are looking for, edit the few files according to the instrux, ftp it to their server, then chmod.&lt;/p&gt;
&lt;p&gt;This is the group I am targeting. Anyone who knows how to write CGI scripts should be more than capable of understanding the CGI security guides that are already available. &lt;/p&gt;
&lt;p&gt;Basically, you only need to learn a few steps to be able to load a free CGI program onto your server. But these people do not know nearly enough to understand the security risks involved with some of the programs they are loading.&lt;/p&gt;
&lt;p&gt;They either don&#039;t take the time to read the current security guides, or the terminology or presentation is just a bit over their heads.&lt;/p&gt;
&lt;p&gt;We are just looking for a short but sweet guide in plain english, telling them why they need to think twice before uploading a script.&lt;/p&gt;
&lt;p&gt;As an example: we can give just a few simple step by step instrux on how to load either a formmail or off site search engine to someone&#039;s site.&lt;/p&gt;
&lt;p&gt;They are very simple steps, anybody who can read and has access to their server could implement these scripts.&lt;/p&gt;
&lt;p&gt;But this does nothing to address the security issue.&lt;/p&gt;
&lt;p&gt;We think it would be irresponsible to explain how to load a script without providing all of the necessary cautions as well.&lt;/p&gt;
&lt;p&gt;We could write it up ourselves, and probably will if no one can help, but we trying to offer the best advice and CGI code is not our specialty, so were looking for outside help if possible.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Greg&lt;/p&gt;
&lt;p&gt;[This message has been edited by CLYMB (edited 25 June 2000).]&lt;/p&gt;
 </description>
     <pubDate>Fri, 23 Jun 2000 07:04:00 +0000</pubDate>
 <dc:creator>CLYMB</dc:creator>
 <guid isPermaLink="false">comment 1005123 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/looking-absolute-beginners-guide-cgi-security#comment-1005122</link>
    <description> &lt;p&gt;I think it would be nearly impssible to write a simple guide to explain CGI security to someome who doesn&#039;t even know how to CHMOD a file. &lt;/p&gt;
&lt;p&gt;Someonce once told me (i really like this quote btw) &quot;It&#039;s not Perl thats insecure it&#039;s your code.&quot;&lt;/p&gt;
&lt;p&gt;You may want to put that up just to get peoples attention.  &lt;img src=&quot;http://www.webmaster-forums.com/ubb/smile.gif&quot; alt=&quot;&quot; class=&quot;bb-image&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Do you need this guide for people who are writing their own programs or installing other peoples programs to the server?&lt;/p&gt;
 </description>
     <pubDate>Thu, 22 Jun 2000 09:36:00 +0000</pubDate>
 <dc:creator>Orpheus</dc:creator>
 <guid isPermaLink="false">comment 1005122 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
