MUSEUM-L Archives

Museum discussion list

MUSEUM-L@HOME.EASE.LSOFT.COM

Options: Use Forum View

Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Jim Angus <[log in to unmask]>
Reply To:
Museum discussion list <[log in to unmask]>
Date:
Tue, 28 Jan 1997 08:18:23 -0800
Content-Type:
text/plain
Parts/Attachments:
text/plain (41 lines)
If someone had enough incentive and knowledge, our server could be readily
pilfered.

We are using several cgi scripts on our server, this means that we give the
world read write and execute permission on those files.  This could serve
as an entry point for someone with a lot more knowledge than I've got.

Our network is not especially secure either.  One disgruntled or naive
employee could run software on his machine which could open up the whole
network to outside attack.

However, our museum is hardly a favoured hacker's target, and if we ever do
have trouble, we'll be able to justify the expense to make the network
really safe.

Jim

>My chief curator is concerned about security as we venture onto the
>web.  Does anyone know if people really can access other non-posted
>information off our terminals? Can someone find the database that
>includes our inventory and "steal" info about values and storage
>locations for instance?  Can the database be corrupted?  Your help is
>appreciated.  I thought I knew about computers but this one has me
>stumped.

Jim Angus
Internet and Hypermedia Programs
Natural History Museum of Los Angeles County
900 Exposition Blvd.
Los Angeles, CA  90007

http://www.nhm.org/nhm

voice:  213/744-3317
fax:    213/746-2999
eMail:  [log in to unmask] = [log in to unmask]
        [log in to unmask]
        [log in to unmask]
        [log in to unmask]
        [log in to unmask]

ATOM RSS1 RSS2