hmmm interesting. Maybe someone with WebDav experience can help.
Sorry
-----Original Message-----
From: "Vital Touch DJs" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Date: Fri, 2 Aug 2002 18:40:24 -0500
Subject: [sambar] WebFolders Trial {03}
> Yes, I have directory Listings turned off so it will come up with an
> unauthorized page if you just try to view a directory.
>
> When FTPing into the server, it comes up in the user's home directory,
> just
> like when you login using the Desktop feature to check your e-mail and
> go
> into the document manager.
>
> But, Web Folders are still available under the My Network Places. You
> just
> create a new network place, and enter the URL of the server. It will
> then
> prompt for a username and password. Basically, anybody that I have on
> the
> server can log into any domain that I host and see the contents of that
> directory, and they can also log in to just the IP address of the
> server as
> well.
>
>
> ----- Original Message -----
> From: "Peter" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Friday, August 02, 2002 6:32 PM
> Subject: [sambar] WebFolders Trial {02}
>
>
> > I don't have a browser here with webfolders so I'm at a loss to do
> any
> > testing. However it is probably based on ftp, have you set your ftp
> > permissions globally or on a per user per vhost basis? Another thing
> that
> > comes to mind is do you have file lists turned off? They really
> should be.
> >
> > Peter
> >
> > ----- Original Message -----
> > From: "Vital Touch DJs" <[EMAIL PROTECTED]>
> > To: <[EMAIL PROTECTED]>
> > Sent: Friday, August 02, 2002 7:12 PM
> > Subject: [sambar] WebFolders Trial {01}
> >
> >
> > Hi all,
> >
> > I again was testing the WebFolders issue.
> >
> > I did as one of the mailing list users said to do; I converted a
> couple of
> > basic sites to a vhosts directory in the root of the server.
> >
> > When I log in using the IP address of the server, I cannot see those,
> since
> > they of course are in a different directory.
> >
> > However, there still is a security issue. I can log in as another
> user,
> and
> > use WebFolders to a domain that the user shouldn't have access to.
> They
> > can't change or delete anything in that directory, but they sure can
> view
> > every single file that is there.
> >
> >
> > Brian Spraker - Owner
> > Vital Touch DJs
> > http://www.vtdj.com
> > Phone: (217) 345-9355
> > Pager: 1-800-412-8274 (Illinois Only)
> >
> >
> > -------------------------------------------------------
> > To unsubscribe please go to http://www.sambar.ch/list/
> >
> >
> > -------------------------------------------------------
> > To unsubscribe please go to http://www.sambar.ch/list/
> >
> >
> >
> >
> >
> -------------------------------------------------------
> To unsubscribe please go to http://www.sambar.ch/list/
>
>
-------------------------------------------------------
To unsubscribe please go to http://www.sambar.ch/list/