Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Jan 2001
Posts: 4
Junior Member
Junior Member
Offline
Joined: Jan 2001
Posts: 4
Was wondering if this was possible. I don't think it is, but i'm not sure. If it is possible, then there really isn't any such thing as security on any .cgi board.

I'm only referring through http btw, not ftp. And more specifically, Apache web servers.

I'm asking because I've been trying to secure my website, and one of the ways I did this was to use htaccess passwords for various files. However, I realized my .htpasswd file was vulnerable to viewing, so I renamed it .htpasswd.cgi.

I also renamed my UltBB.setup file to UltBB.setup.cgi so that directories would be hidden.

[ February 23, 2001: Message edited by: shingen ]

Sponsored Links
Joined: Nov 2000
Posts: 168
Member
Member
Offline
Joined: Nov 2000
Posts: 168
Well I've seen many cases where the server is having errors and did not excute the script and allowed me to download them. Which was a big security thing....

Joined: Aug 2000
Posts: 335
Member
Member
Offline
Joined: Aug 2000
Posts: 335
It depends on whether the server is configured properly.

Whenever possible, files that do not need to be accessed directly by a web browser (i.e., by URL) should be located outside the web document root.

This applies especially to .htpasswd files.

Joined: Jan 2001
Posts: 4
Junior Member
Junior Member
Offline
Joined: Jan 2001
Posts: 4
if the server is a microsoft web server, it might be vulnerable to viewing the source by opening something like this in your browser: http://www.victim.com/cgi-bin/Ultimate.cgi+.htr

That's the only bug I know.

[edit]
typo
[/edit]

[ February 23, 2001: Message edited by: Rene59 ]

Joined: Feb 2001
Posts: 18
Junior Member
Junior Member
Offline
Joined: Feb 2001
Posts: 18
Quote
quote:
And how exactly does that make directories hidden?

Sponsored Links
Joined: Jan 2001
Posts: 4
Junior Member
Junior Member
Offline
Joined: Jan 2001
Posts: 4
Well, not hidden. But certainly not accessible by simply looking at an UltBB.setup file. Yes, some files are called upon in various directories, but I'd like it if somebody didn't know where my member directory was, etc...

I'm also using htaccess to call a custom error handling script that logs all IPs, in addition to index.html files that point to this error script. It comes in handy for logging people that like to snoop around.

Oh, and thanks Dave_L for that tip about putting .htaccess files outside web document root. Didn't think about that option. laugh

[ February 24, 2001: Message edited by: shingen ]

Joined: Jul 2000
Posts: 1,349
Ell Offline
Member
Member
Offline
Joined: Jul 2000
Posts: 1,349
I can't for the life of me remember how to do it, but there's a


order deny,allow
deny from all


Type-thing that lets you deny browser access to .htaccess and .htpasswd files, that could also be adapted for .setup, I guess...


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Posts: 70
Joined: January 2007
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240506)