CGI-BIN directory under Nescape's WWW Server

CGI-BIN directory under Nescape's WWW Server

Post by Gerry Gin » Thu, 26 Sep 1996 04:00:00



I need help setting up a CGI-BIN directory for student class assigments. It
appears that if CGI scripts are stored in /usr/ns-home/https-80/cgi-bin they
run as ROOT which NOT a good thing to do!!!


Thanks

 
 
 

CGI-BIN directory under Nescape's WWW Server

Post by Phon » Sun, 29 Sep 1996 04:00:00


you mean you give student root acces to CGI-BIN to run their program ?
hmmm that not good,
,assum that the dir for web page is public_html , tell them to make a
sub directory cgi-bin with in the  public_html , or if you want you can
make another cgi dir for them , it doesn't have to be call cgi-bin , it
can just be cgi after that reconfig the Web server to  let it know that
you have additional cgi dir in your web server

Phong

**************
http://www.cloud9.net/~phongng
*************


> I need help setting up a CGI-BIN directory for student class assigments. It
> appears that if CGI scripts are stored in /usr/ns-home/https-80/cgi-bin they
> run as ROOT which NOT a good thing to do!!!


> Thanks


 
 
 

1. /cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

I've been seeing a number of attacks of this sort recently
from various sites in the http logs.  The time correlation
between the logs on various hosts suggests that the attacker
was scanning sequentially upward in IP addresses.  Since all
tcp and udp packets to ports below 1024 except for http,
smtp, and ident are filtered out for most, including the
attacking, sites, I'm not seeing anything else in the logs.

209.61.73.47 - - [04/Jul/1998:07:19:27 -0500] "GET /cgi-bin/phf" 404 -
209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/test-cgi" 404 -
209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/handler" 404 -

Is this a signature of some known attackware?  If so, what
other attacks accompany these http probes?

--

2. Backup

3. cgi-bin and www directories

4. It's a religious war....

5. Can't get CGI to run in local cgi-bin directory

6. Linux - PPP on Compaq Presario? Winmodem?

7. Aliasing cgi-bin directory to CGI directory

8. SLIPP Dial up Software and WWW Browser

9. Q: user's own cgi-bin directory?

10. cgi-bin/view-source?cgi-bin/view-source

11. Can't access cgi-bin directory

12. can't write to cgi-bin directory

13. cgi-bin's in user directories