Changeset 992
- Timestamp:
- 05/08/03 14:48:00 (22 years ago)
- Files:
-
- 1 modified
Legend:
- Unmodified
- Added
- Removed
-
pykota/trunk/SECURITY
r971 r992 80 80 can read PyKota's configuration file too, for example 81 81 by putting www-data in the lpadmin group. 82 WARNING : putting www-data in the lpadmin group so that 83 the CGI script can read the /etc/pykota.conf file is 84 dangerous. If any user can create CGI scripts launchable 85 as www-data then he could steal a copy of the /etc/pykota.conf 86 file and learn database and database users' name and passwords. 87 The best solution is probably to create a pykota system 88 account and run the CGI script as this user using Apache's SuEXEC 89 facility. Refer to Apache's documentation for details. 82 90 83 91 - Secure your database connection :