See the security of CGI from a installation file

zhaozj2021-02-16  48

Old version of the article, I found out that I haven't intended to find it today, I will publish and this: I published and the old version of the West Road, the old version of the West Road, the old version of the Western Road, I haven't intended to be found. I found that when I have just launched a 2.0 version, I have a fatal error. Originally this error can be avoided, but I have always been defective. At the time, I was still in the end of September. I can't remember anyway. You can take a look at the 2.1 version is a long time to know, 2.1 Security version Previous day, I was shocked by a test message. He said that security is too bad and clearly indicates that the setup.txt file can be browsed directly, and feedback to any person's super administrator name and password. He threatened: "Don't tell me all your passwords." I actually all my passwords, including the server. Fortunately, he just reminded. I immediately modified this error. But therefore leads to some thinking! First, .txt files are used to do the installation information file is intended to speed up the running speed of Perl, but did not think that .txt will be browsed, if it is .cgi file (only to extension, change), this kind Question, because the installation information inside does not print "content-type: text / html / n / n"; it will not be output to the browser. There is an attribute problem. It turns out that it doesn't matter if it can run, but it is wrong. If the property is set to 666, maybe theoretically will not disclose, but I tried .txt, or back to the browser! So the decline of Perl enthusiasts should not pursue the speed, and it is also important.

转载请注明原文地址:https://www.9cbs.com/read-25816.html

New Post(0)