Stephen Turner wrote:
> On Sun, 7 Nov 1999, Jeff Longland wrote:
>
> > Perl for Win32 isn't installed so the form for the new
> > version of Analog isn't of assistance for me! The executable version
> > that everyone keeps recomending will only work with almost all of my
> > analog directory in the cgi-bin. Then this causes a security risk!
>
> Jeremy's certainly aware of these security discussions (at least until his
> mail went down at the end of last week), and I think he will produce another
> executable version which doesn't require analog to be in cgi-bin. I think he
> was talking about having a single file in cgi-bin which would specify the
> location of analog.
> Is anyone other than Aengus using the form interface? I've made a new
> version which you can pick up from
> http://www.statslab.cam.ac.uk/~sret1/analog/anlgform.pl
> Of course, you're all welcome to test it, but the main changes are on
> Windows, so I'd be particularly grateful for people using Windows to give me
> some feedback. It should now cope with spaces in the $analog variable.
>
Let me catch up on any security discussions I may have missed and try out the
new form interface. If it all looks good to me I'll try to post an executable
version of the script today or early tomorrow.
The suggestion I made to Stephen was to make the executable version of the
script look in its own directory for a file called anlgform.cfg that contains
the location of the analog.exe executable on the Windows system. This still
includes a security problem, becaues this file will be readable by the web user
and analog.exe must be executable by that user. I don't know of any way around
this; any suggestions would be appreciated.
--
Jeremy Wadsack
-------------------------------------------------------------------------
Wadsack-Allen Digital Group Digital Media Publishing Specialists
http://www.wadsack-allen.com/digitalgroup/ +01-520-213-8530
-------------------------------------------------------------------------
------------------------------------------------------------------------
This is the analog-help mailing list. To unsubscribe from this
mailing list, send mail to [EMAIL PROTECTED]
with "unsubscribe analog-help" in the main BODY OF THE MESSAGE.
List archived at http://www.mail-archive.com/[email protected]/
------------------------------------------------------------------------