Hi all,

I just modified RenameFile to make sure that the
source file and destination file are both in the DQSD
installation directory tree.  I didn't want someone to
maliciously rename key windows dlls or anything
outside the DQSD realm.

We also should probably not allow them to rename
system type files like dlls and exes (even in the DQSD
dir) either, right?

We should also probably limit WriteFile with the same
restrictions as RenameFile as well.

And finally, maybe even ReadFile shouldn't be able to
do anything outside the DQSD installation dir.

Your thoughts?

Brent
 

__________________________________
Do you Yahoo!?
SBC Yahoo! DSL - Now only $29.95 per month!
http://sbc.yahoo.com


-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
DQSD-Devel mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/dqsd-devel

Reply via email to