Instant ASP Logo

IMPORTANT SECURITY ADVISORY

With the current (1.0.5) and older iASP builds, ASP scripts in any virtual (public) directory can be executed with the same permissions as that of the user who is running the iASP server and iASP administration server.  Therefore, ASP scripts/applications have permissions on all the files and directories that the user does.

This can potentially lead to security holes in cases when you run iASP as 'root' and do not have full control over the ASP applications that are being deployed.  An example of that can be the File I/O sample when run with the wrong permissions.

It is, therefore, recommended that you run iASP as a user whose permissions are set according to your specific needs.  For instance, you can create a user 'iASP' that has restricted read/write access to a specified directory.  The ASP scripts from this point on will only have access to this particular directory.

A security scheme is has been put in place as a matter of urgency. Once fully tested, it will be made available to our users either as part of the 1.0.3 build or as a patch - whichever is sooner.

NOTE: The samples distributed with iASP are for demonstration purposes only.  These samples are not intended as ASP applications sitting on production systems and we advise you to grant public access to them only after reviewing their functionality thoroughly.  For instance, the File I/O sample should not be made publicly accessible unless you are sure that this exactly what you wish to do.
 


Copyright © 1998-2000, Halcyon Software Inc. All rights reserved.