Re: using cgi-bin

by "Harold A. Driscoll" <harold(at)driscoll.chi.il.us>

 Date:  Sun, 07 Nov 1999 22:41:18 -0600
 To:  Keith(at)WebGraffix.com
 Cc:  Bob Maine <maine(at)2alpha.net>, joni(at)guidinghands.org, hwg-servers(at)hwg.org
 References:  2alpha
  todo: View Thread, Original
At 19:17 05-11-99 , Keith wrote:
>Bob Maine wrote:
>> So let me get this straight. You are a rank beginner programmer who wants
>> to play around with executable scripts on someone else's server, caring
>> not whether you trash hundreds or even thousands of other peoples sites
>> and ruin your hosts business reputation, and your miffed because he
>> doesn't think this is a good idea?

You're not pulling any punches here, nor sugar-coating the harshness of
reality.

>> Set up your own machine at home with NT and IIS and 
>> learn to program there at your own risk like every one else.  [...]

Wise advice. I'd generalize that to "NT and a Web server." Personally I'd
think that IIS (and PWS) is perhaps the most difficult route; there are
better choices, particularly Apache. But to each their own tastes or needs.

>I think your response is completely unnecessary.  

Nope. Not at all. It was blunt, yes, but quite factual.

>Obviously, this person has a legitimate question.  

Yes, and got a very legitimate (and appropriate) response.

>I am able to write and execute my cgi scripts without 
>affecting anyone else's whatsoever.  

Perhaps you have not. Such is neither surprising nor predictable.

If you toss a lighted match into a pan of gasoline, quite possibly it will
not explode. However, it is hardly neighborly nor reasonable to do such
things in a manner that may be exposing others to risk.

One needs to look at the technology (e.g. chemistry of flammable liquids or
running particularly potent programs with minimal protection in a
live-server environment) to assess risks. That something didn't cause
adverse results (whether tossing the match, running the CGI script, or any
number of other activities.... only tells you that you didn't get hurt that
time.

>I am NOT a beginner and have done lots of sites, some very 
>simple and some very, very complicated.

Are you arguing that there is no risk, and that other applications on the
server are fully protected, and hence are without risk from the possible
errant behavior of a CGI script? Or are you stating that such awareness is
not within your knowledge?

Are arguing that it is possible to verify the total correctness of a
program? If so, you've a vast field of computer science and information
technology to convince. If not, then Q.E.D. for the prior post, don't you
think?

>Give the new ones a break.  After all, we were all unlearned and
>ignorant of the inner workings of website design at one point.

Yes, that is precisely what the sage advice was doing.

When a child is hazardously playing with matches, it is hardly abuse to
swat them out of their hand. Much the same with the reply in question. It
offered advice on how to play safe. Sound advice.

Safe computing,  /Harold

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Harold A. Driscoll                       mailto:harold(at)driscoll.chi.il.us
#include <std/disclaimer>      http://homepage.interaccess.com/~driscoll/

HWG: hwg-servers mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.