[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: htsearch wrapper files



Sounds great!  I don't understand why reading the wrapper's would be a
security risk at all...?  Sum1 wish to inform me?

Jason


On Thu, Mar 25, 1999 at 09:19:47PM -0800, Aaron D. Turner wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> 
> 
> Great news.  We don't need a bazillion config files if rumor is correct.
> 
> We just add this to the htdig.conf file.
> 
> allow_in_form:  mywrapper
> mywrapper:      foo
> search_results_wrapper: ${common_dir}/${mywrapper}wrapper.html
> 
> Then add to each search form:
> 
> <type=hidden name=mywrapper value=[CategoryID]>
> 
> Then generate the appropriate wrapper files:
> 
> /home/htdig/dev/common/[CategoryID]wrapper.html
>             ^^^
>             Change as appropriate
> 
> One minor catch though.  Somone could use this to view any file that the
> webserver has read access to that ends in "wrapper.html".  They'd have to
> know the path of course, but since I doubt we'll have many *wrapper.html
> files, I doubt that this is much of an issue.
> 
> I have yet to actually test this out, so this is only preliminary.  When I
> find out more, I'll pass it along.
> 
> 
> - -- 
> Aaron Turner           | Either which way, one half dozen or another. 
> aturner@pobox.com      | Check out the Red Hat Linux User's FAQ Online!
> www.pobox.com/~aturner | http://www.pobox.com/~aturner/RedHat-FAQ/
> All emails from this account are PGP signed.  Lack of a signature is "bad".
> PGP Key fingerprint = FB E1 CE ED 57 E4 AB 80  59 6E 60 BF 45 1B 20 E8
> 
> 
> 
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
> 
> iQCVAwUBNvsY9TM3jpXy1kJtAQFMIwP9EU7ITRdwdc6kVwQji8gK4EbFWfRMTdaj
> FyjKwOGS0ZUvthIU3JSd3FAQpMMLHCDbpEBTzrXxrrQ+QXKShwlnMMk2iqELTl+R
> glwti7ublNOTXfxJDqtk2O95HwAcz9kU1j1Q+EKwVgNbYzOqcFV43NrnPYiCRE8b
> XAB5BzMKlsk=
> =H58T
> -----END PGP SIGNATURE-----
---end quoted text---