[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: htsearch wrapper files
Sounds great! I don't understand why reading the wrapper's would be a
security risk at all...? Sum1 wish to inform me?
Jason
On Thu, Mar 25, 1999 at 09:19:47PM -0800, Aaron D. Turner wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
>
>
> Great news. We don't need a bazillion config files if rumor is correct.
>
> We just add this to the htdig.conf file.
>
> allow_in_form: mywrapper
> mywrapper: foo
> search_results_wrapper: ${common_dir}/${mywrapper}wrapper.html
>
> Then add to each search form:
>
> <type=hidden name=mywrapper value=[CategoryID]>
>
> Then generate the appropriate wrapper files:
>
> /home/htdig/dev/common/[CategoryID]wrapper.html
> ^^^
> Change as appropriate
>
> One minor catch though. Somone could use this to view any file that the
> webserver has read access to that ends in "wrapper.html". They'd have to
> know the path of course, but since I doubt we'll have many *wrapper.html
> files, I doubt that this is much of an issue.
>
> I have yet to actually test this out, so this is only preliminary. When I
> find out more, I'll pass it along.
>
>
> - --
> Aaron Turner | Either which way, one half dozen or another.
> aturner@pobox.com | Check out the Red Hat Linux User's FAQ Online!
> www.pobox.com/~aturner | http://www.pobox.com/~aturner/RedHat-FAQ/
> All emails from this account are PGP signed. Lack of a signature is "bad".
> PGP Key fingerprint = FB E1 CE ED 57 E4 AB 80 59 6E 60 BF 45 1B 20 E8
>
>
>
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
>
> iQCVAwUBNvsY9TM3jpXy1kJtAQFMIwP9EU7ITRdwdc6kVwQji8gK4EbFWfRMTdaj
> FyjKwOGS0ZUvthIU3JSd3FAQpMMLHCDbpEBTzrXxrrQ+QXKShwlnMMk2iqELTl+R
> glwti7ublNOTXfxJDqtk2O95HwAcz9kU1j1Q+EKwVgNbYzOqcFV43NrnPYiCRE8b
> XAB5BzMKlsk=
> =H58T
> -----END PGP SIGNATURE-----
---end quoted text---