SimpleXMLRPCServer security

R

Robin Becker

What are the security issues for an xmlrpc server with 127.0.0.1 as
host? Clearly anyone with local access can connect to the server so we
should protect the server and client code, but in my particular case the
client starts as a cgi script and in general must be world
readable/executable. Switching uid at startup allows the client code to
be private; so is that a strategy for protecting the
encryption/decryption which obfuscates the xmlrpc channel?

Anyone done this sort of thing before?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
474,241
Messages
2,571,219
Members
47,849
Latest member
RoseannKoz

Latest Threads

Top