OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: anonymous ftp server
From: Joe Laffey (joeLAFFEYCOMPUTER.COM)
Date: Sun Sep 10 2000 - 20:52:05 CDT


On Sun, 10 Sep 2000, C. Higgins wrote:

> That's very true, enabling a webservers fancyindex option can open up a
> very large security hole.

How is this a large security hole if you (correctly) only allow indexes
for the particular directory in question? If you control write access to
the directory what are the potential problems? (Of course you must set up
ownership of the icons correctly too...)

Thanks,

Joe Laffey
LAFFEY Computer Imaging
St. Louis, MO
-------------------------
With no walls or fences on the Internet, who needs Windows or Gates?
---------------------------------------------------------------------