Re: WebCatalog security on NT
This WebDNA talk-list message is from 2000
It keeps the original formatting.
numero = 27184
interpreted = N
texte = > >Hi,> >> >I would like to suggest a customer to offer webcat, on their NT web> >hosting systems.> >> >I have seen some posts from Ken, and I know that is the case on a> >Mac, that somebody with upload capabilities, could possibly cause *a> >lot* of trouble, deleting files, running applescripts, messing with> >the TCPSend command, and so on> >> >The customer offers web hosting services, with virtual domains, on >an NT box.> >> >Can webcat be told to run only in certain folders?>>No, that's the major problem preventing it from being a secure >hosting tool. Webcat on NT can run DOS commands/scripts, so nothing >is safe on NT, just like nothing is safe on Macintosh. Even without >AppleScript/DOS contexts, webcat's ability to navigate the folder >hierarchy with its standard features puts other sites in danger of >being hacked quite easily.Thanks Ken,That was a pretty fast response...So I assume that since people *do* host sites on NT, they still must have devised a method of doing that... What are the prevention steps that could be taken do have a somewhat secure hosting.The same hosting box runs ColdFusion, Could ColdFusion navigate folder hierarchy, like webcat? Because if that's the case, I could suggest disabling the DOS commands, and then it would be posing the same risk as CF.Serban-------------------------------------------------------------Brought to you by CommuniGate Pro - The Buzz Word Compliant Messaging Server.To end your Mail problems go to
.This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to
Associated Messages, from the most recent to the oldest:
> >Hi,> >> >I would like to suggest a customer to offer webcat, on their NT web> >hosting systems.> >> >I have seen some posts from Ken, and I know that is the case on a> >Mac, that somebody with upload capabilities, could possibly cause *a> >lot* of trouble, deleting files, running applescripts, messing with> >the TCPSend command, and so on> >> >The customer offers web hosting services, with virtual domains, on >an NT box.> >> >Can webcat be told to run only in certain folders?>>No, that's the major problem preventing it from being a secure >hosting tool. Webcat on NT can run DOS commands/scripts, so nothing >is safe on NT, just like nothing is safe on Macintosh. Even without >AppleScript/DOS contexts, webcat's ability to navigate the folder >hierarchy with its standard features puts other sites in danger of >being hacked quite easily.Thanks Ken,That was a pretty fast response...So I assume that since people *do* host sites on NT, they still must have devised a method of doing that... What are the prevention steps that could be taken do have a somewhat secure hosting.The same hosting box runs ColdFusion, Could ColdFusion navigate folder hierarchy, like webcat? Because if that's the case, I could suggest disabling the DOS commands, and then it would be posing the same risk as CF.Serban-------------------------------------------------------------Brought to you by CommuniGate Pro - The Buzz Word Compliant Messaging Server.To end your Mail problems go to .This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to
Serban Constantinescu
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
b12 cannot limit records returned and more. (1997)
[WebDNA] anyone use curl with shell? (2010)
db merge problem (2002)
syntax question, not in online refernce (1997)
error message (2000)
Secure Sever and showcart errors (1997)
Formating Tables w/[founditems] (1998)
Problems with cybercash (2000)
Online magazine- monthly updates and such (1999)
Modifying order output (1997)
Bug? (1997)
Date search - yes or no (1997)
[OT] Games (2005)
Setting up WebCatalog with Retail Pro data (1996)
WebCat2b13MacPlugin - [math][date][/math] problem (1997)
protect tag on NT IIS (1997)
problem serving foreign languages text (1997)
BUG in [showif] using ^ (contains) (1997)
form data submission get (1997)
denying access to a banned username (2002)