On Thu, Feb 03, 2011 at 08:15:26PM +0100, Stephan Beal wrote:
> 2011/2/3 Lluís Batlle i Rossell <virik...@gmail.com>
> 
> >  If you don't use a root account for your CGI, you can use a setuid program
> > for
> > it to have such access to your files. Something like this here explained,
> > but
> > applied to fossil:
> > http://vicerveza.homeunix.net/~viric/c<http://vicerveza.homeunix.net/%7Eviric/cgi-bin/offrss/doc/trunk/doc/cgi.wiki>
> >

> setuid scripts are an option, but are an ugly ancient remnant of "more
> civilized times" and are generally frowned upon for security reasons. If i'm
> not mistaken (and i might be), recent Linux versions ignore the setuid bit
> (or only allow it on a configurable list of files).
And this is why that web page suggests a C program. :)

Regards,
Lluís
_______________________________________________
fossil-users mailing list
fossil-users@lists.fossil-scm.org
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to