web designweb site design Online Store  web design My Account   About Us web design company Contact Us free web design Support web site design company1 800 695-6200
cobalt raq servers
low cost dedicated hostingdedicated web server
Wed Aug 27 2008
Network Traffic Probe
dedicated web hosting dedicated hosting dedicated server
WHAT'S NEW

 

RaQ3/RaQ4: Security vulnerability

09.24.2003

A vulnerability in the GUI of the RaQ3 and RaQ4 can lead to undue disclosure of information.
The directory in which Analog stores its report files lacks proper .htaccess protection and can therefore be viewed without authentication.

To prevent this run the following command as root:

cp /usr/admserv/html/.cobalt/services/.htaccess /home/.cobalt/report/.htaccess

That will copy a .htaccess file to that directory and will make sure that only user admin can view the Analog report files.