Re: [naviserver-devel] Source of non executable CGI scripts are shown

2017-10-20 Thread Roderick
This is different to other servers, which do not allow this. ... and apparently, this is for you unexpected behavior - which can lead to revealing unwanted information, when not carefully set up. Well, I though it was a bug, but it is indeed a feature. One needs only to be carefull. I do not

Re: [naviserver-devel] Source of non executable CGI scripts are shown

2017-10-19 Thread Gustaf Neumann
Am 17.10.17 um 1:15 PM schrieb Roderick: If a cgi script is readable, but not executable, the server sends its source as text. Is this not a security problem? NaviServer allows to serve cgi-programs AND included content (images, css, ...) from a cgi-bin directory. In order to identify in a cgi

[naviserver-devel] Source of non executable CGI scripts are shown

2017-10-17 Thread Roderick
Dear Sirs, If a cgi script is readable, but not executable, the server sends its source as text. Is this not a security problem? Rodrigo. -- Check out the vibrant tech community on one of the world's most engaging te