Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Search

 
Advanced search

8040 Posts in 1853 Topics- by 2099 Members - Latest Member: roi
Calendar Script CommunitySetup and InstallationInstallation and Setup (Moderators: scott, DanO, Marty)No real security on multiple calendars. You Can read everything
Pages: [1]   Go Down
Print
Author Topic: No real security on multiple calendars. You Can read everything  (Read 250 times)
0 Members and 1 Guest are viewing this topic.
detroitdr
Guest
« on: August 11, 2005, 11:10:00 AM »

I've been looking at this program, and although it's a VERY good program, if you use more then 1 calendar, you really have no security.

For example, you do not have to sign in to read all the data. Using your site as an example you have a RESTRICTED calendar called LIMITED. Click below to read all your data (which clears out... but the file is readable) without the need to login. I've gone around to some other locations that have left their calendars in your support forum and they two (if multiple calendars) have this "hole".
http://www.calendarscript.com/demo/calendarscript/calendars/limited/events.txt

I hope you can figure a way to plug it up for people who want to manage multiple calendars.

Now knowing this... if someone uses more then 1 calendar, then the directory name will be known (without login) and all you need to do is remove the calendar.pl with

calendarscript/calendars/***calendar name***/events.txt


If only one calendar is used then it would be much harder to get the directory name unless they left it as default....

Hope this helps increase the security someday...

DetroitDr

Logged
detroitdr
Guest
« Reply #1 on: August 11, 2005, 11:29:00 AM »

Just checking a little bit more and it's actually easy to find out the directory names of the calendar even if it's the only one... so now that opens up even single calendar security.

Example again from your site,
http://www.calendarscript.com/demo/calendarscript/calendars.txt

Now is this perhaps an issue with MS IIS versus another platform?

DetroitDr

Logged
DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 227

Please don't PM me. Post in the open forum.


WWW
« Reply #2 on: August 11, 2005, 12:25:00 PM »

** I hope you can figure a way to plug it up for people who want to manage multiple calendars. **

It's not brain science, just set up your server properly and you won't have any problems. Just deny 'read' permissions to the calendarscript data directories.

JMO

Dan O.

------------------

Logged
Pages: [1]   Go Up
Print
Jump to: