>It seems to me, as I explained before, that this is a serious security
>risk. Of course, I can warn people about it, but they won't necessarily
>know, or be able to find out easily, whether their server is an at-risk one.
>Or even read the instructions.
>At this moment, I'm minded to remove the CGI command from analog altogether,
>and only allow CGI access via This is in some ways less
>convenient, but I don't think I can advertise a feature when it's very
>likely to be set up as a security risk.

I'd vote for removing the CGI command - one of the things that analog
has going for it is that it's simple to use, simple to set up.  When
you start getting into security issues like this, all of a sudden
it's NOT simple to use/set up and people are liable to get bitten.

(Admit it - how many people out there really read ALL the docs?)


