[wplug] Debate question: cgi-bin vs. htdocs

James O'Kane jo2y at midnightlinux.com
Mon Jan 6 13:07:23 EST 2003


If you've ever setup apache, you've probably seen cgi-bin that is special 
directory. I had been told that server side execuatables should go there 
because often the site admin would want to look over the script to make 
sure it doesn't do anything stupid like "dd if=/dev/zero of=/etc/passwd", 
but now in the days of PHP and Mason, etc. I've seen a trend to just make 
anything in htdocs scriptable. The line between 'safe' files and scripts 
is now very blurred.
Good? Bad? Comments?

I'm not really looking for a true answer, I'm just curious what people 
think.

-james





More information about the wplug mailing list