OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: CGIs running on Windows
From: - Evil (ev1ldkYAHOO.COM)
Date: Mon Oct 09 2000 - 06:57:29 CDT


Since we have been discussing CGIs here, I would like
to address
a certain issue. We all know how dangerous CGI scripts
can
be - and we have seen many examples of it - and will
for a
long time. However it seems like the authors of CGIs
take
security less seriously if their script is meant for
Windows
- i.e. when doing open's. Does this mean that a:

open FILE, "$some_user_controllable_input;

is secure on a machine running Windows? At least on
machine
running *nix it would be a big security hole.

thanks!

__________________________________________________
Do You Yahoo!?
Yahoo! Photos - 35mm Quality Prints, Now Get 15 Free!
http://photos.yahoo.com/