AsiaBSDCon 2017 Secure CGI

CGI security mechanisms

CGI security mechanisms

What can we do?

Many mechanisms depend upon web server configuration, which is not reliable. If running as root, application can try to jail its file-system and drop privileges. (Meditation: a web server running its scripts as root will have other issues.)