473,432 Members | 1,583 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,432 software developers and data experts.

I/O and Security Considerations

My web app needs to write text and .jpg/.gif files to disk (e.g., the user
can upload photos which are then made available for viewing in the app's
pages). The folder(s) to which the files are written can be placed below the
site root (i.e., "in" the site), or above the site root.

The hosting provider I'm working with insists that the folder to which the
app writes files be placed outside of (above) the site root folder.

I'm just wondering what the security risk is of having the folder in the
site (i.e., below the site root folder).

Is my hosting provider following some well-accepted best practice; or does
it not really matter where the folders are as long as the NTFS permissions
are no more than necessary?

Thanks
Nov 19 '05 #1
1 1018
your provider is correct. by putting application data files outside of the
vdir, only your app can access them, iis can not serve them up directly.

-- bruce (sqlwork.com)

"Jerry" <no****@nospam.org> wrote in message
news:%2***************@TK2MSFTNGP10.phx.gbl...
| My web app needs to write text and .jpg/.gif files to disk (e.g., the user
| can upload photos which are then made available for viewing in the app's
| pages). The folder(s) to which the files are written can be placed below
the
| site root (i.e., "in" the site), or above the site root.
|
| The hosting provider I'm working with insists that the folder to which the
| app writes files be placed outside of (above) the site root folder.
|
| I'm just wondering what the security risk is of having the folder in the
| site (i.e., below the site root folder).
|
| Is my hosting provider following some well-accepted best practice; or does
| it not really matter where the folders are as long as the NTFS permissions
| are no more than necessary?
|
| Thanks
|
|
Nov 19 '05 #2

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

1
by: BijuThomas | last post by:
Complicated - ASP/Security/data transfer/XML doubt In our company Head office we are hosting an intranet server in IIS (Windows 2000) , ASP and Sqlserver back end. We are maintaining our branch...
5
by: peteh | last post by:
We are running DB2 PE (AIX) 8.1.5 and have built a SQL stored proc that uses the SNAPSHOT_APPL_INFO udf to return to the caller info about current db2 connections. The SP was created by a user...
116
by: Mike MacSween | last post by:
S**t for brains strikes again! Why did I do that? When I met the clients and at some point they vaguely asked whether eventually would it be possible to have some people who could read the data...
1
by: Andy Fish | last post by:
Hi, I am about to deploy an asp.net web app which will consist of a web server in the DMZ invoking web services hosted inside the corporate firewall. Both will be hosted on IIS 5 or 6 using...
0
by: The Lazy Slug | last post by:
Good Afternoon All, Please excuse my ignorance, as I am a System Administrator, rather than a developer, but I was hoping someone could help me with a security question. We have installed on...
0
by: Mantorok | last post by:
Hi all I don't leave much to chance, I've been thinking about security considerations when deploying a web-site. We have sites in our DMZ and most of these utilise our "internal" database...
4
by: Adrian | last post by:
can someone explain the cross domain security re AJAX in IE? I have a page that calls a web service (WS) from another domain (the target browser is only IE6) and displays it's results! all works...
15
by: himilecyclist | last post by:
My State government organization has written a PHP/MySQL application which has been in production for about 6 months and has been highly successful. We are now embarking on a similar database...
18
by: Earl Anderson | last post by:
First, I feel somewhat embarrassed and apologetic that this post is lengthy, but in an effort to furnish sufficient information (as opposed to too little information) to you, I wanted to supply all...
12
by: yawnmoth | last post by:
A particular web hosting company decided to install phpsuexec on all their webservers, citing security considerations. My question is... is it really more secure? Without phpsuexec, if a PHP...
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing,...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new...
0
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The...
0
by: adsilva | last post by:
A Windows Forms form does not have the event Unload, like VB6. What one acts like?

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.