TWiki Security for Public Sites
Overview
The purpose of this topic is to list recommended practices to help assure security (or at least minimize risk) of using TWiki in public web sites. This was prompted in the aftermath of
SecurityAlertExecuteCommandsWithSearch and follow-up discussions regarding potential vulnerabilities of TWiki used in public sites.
Recommended Actions/Practices:
Contributors:
Discussion & Comments
Resources:
--
MartinCleaver - 01 Dec 2004
--
MartinCleaver - 01 Dec 2004
This should probably be merged with
SecureSetup. Also, I don't think the emphasis on public sites is particularly useful - this could be applicable to intranet TWikis, since an internal machine might be compromised as a launching pad for an attack on a TWiki.
How about calling this
SecureDeployment or something?
--
RichardDonkin - 05 Dec 2004