<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : Disallowed Path Characters</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : Disallowed Path Characters]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 04 Apr 2026 06:34:29 +0000</pubDate>
  <lastBuildDate>Fri, 21 Dec 2007 03:41:37 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=24980</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[Disallowed Path Characters : I just wanted to thank everyone...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130268.html#130268</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=27333">GrlGeek</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 21&nbsp;December&nbsp;2007 at 3:41am<br /><br />I just wanted to thank everyone for your help. As the client had selected GoDaddy for the host, I did end up using the "security by obfuscation" suggestions, and though I know we are skating on thin (and unsupported) ice, I was able to get the forum up and running (with the wimpy Access database). I know we noobs must drive you guys batty with these things, thanks again for being so patient and helpful.]]>
   </description>
   <pubDate>Fri, 21 Dec 2007 03:41:37 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130268.html#130268</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : Is that the regular hosted accounts...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130085.html#130085</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=27333">GrlGeek</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 14&nbsp;December&nbsp;2007 at 4:58am<br /><br />Is that the regular hosted accounts or a dedicated server? We're getting a dedicated (virtual) server, do you know what about the servers is incompatible with Web Wiz? The forum was actually "running" earlier today, in that it would display, but the permissions were not set correctly to allow me to log in, which required a write, I believe. I'd post a link but the server has already been taken down in preparation for moving to the new "assisted" account. I told the tech support during the conference call what I was trying to install, he never mentioned not being able to run it. This server is supposed to be customized to our specifications, it's not one of the vanilla hosted accounts. I hope I can give you some good news in a few days, they did say it might take up to 36 hours to complete the configuration.]]>
   </description>
   <pubDate>Fri, 14 Dec 2007 04:58:46 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130085.html#130085</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : Thanks, y&amp;#039;all. I was able...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130077.html#130077</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=27333">GrlGeek</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 13&nbsp;December&nbsp;2007 at 6:52pm<br /><br />Thanks, y'all. I was able to get the physical path, but I was unable to adjust the permissions on the directory to allow access. GoDaddy uses something called Plesk for the admin interface, and I could see the options I needed, but they were greyed out, even though I was logged in as the server admin. Unfortunately, Web Wiz is not the only added software package I need to run, and the shopping cart has the same issues. The client is switching to a hosting account which will include assistance from the hosting company to get things set up on the virtual dedicated server, so once they get the new server configured I should be able to use the information you've been so kind to share to get things up and running.  <br /><br />SQL is definitely on the agenda (at least it's on MY agenda), but we will probably wait to see if the traffic warrants a switch. The forum has a fairly narrow audience, military veterans seeking civilian career skills assistance, so it may be a while before we have to worry about volume. Of course the client hopes it will be enormous, so I may be back for the SQL version yet. <br /><br />Thanks again for all the help!]]>
   </description>
   <pubDate>Thu, 13 Dec 2007 18:52:06 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130077.html#130077</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : I would recommend using the physical...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130076.html#130076</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=24799">Jono</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 13&nbsp;December&nbsp;2007 at 5:52pm<br /><br />I would recommend using the physical path. You can use the Request.ServerVariables("APPL_PHYSICAL_PATH")&nbsp;to find out what the physical path is (default install gives<strong>&nbsp; </strong>C:\Inetpub\wwwroot\). Then create a random folder name and put your access database in there with random file name and an asp extension.<DIV>As boRg says, some form of SQL server is the way forward. It may be worth considering Web Wiz to host your forum (<a href="http://www.webwiz.net/" target="_blank">http://www.webwiz.net/</A>), if you have any difficulty with your current provider.<BR></DIV>]]>
   </description>
   <pubDate>Thu, 13 Dec 2007 17:52:31 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130076.html#130076</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : You don&amp;#039;t need to have parent...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130075.html#130075</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 13&nbsp;December&nbsp;2007 at 4:24pm<br /><br />You don't need to have parent paths enabled to use Web Wiz Forums.<br><br>If you wish to place the Access database in the root folder, then the physical path would be better.<br><br>However, Access can only handle a handful of users, I would suggest that you look at using either the mySQL version or better still SQL Server version, as these can handle many 1000's of simultaneous connections.<br>]]>
   </description>
   <pubDate>Thu, 13 Dec 2007 16:24:15 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130075.html#130075</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : So, should I opt for the physical...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130073.html#130073</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=27333">GrlGeek</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 13&nbsp;December&nbsp;2007 at 4:00pm<br /><br />So, should I opt for the physical path, is that more secure? And then I'd just need to have the permissions adjusted? I have a conference call with the hosting company today.]]>
   </description>
   <pubDate>Thu, 13 Dec 2007 16:00:07 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130073.html#130073</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : You&amp;#039;re right that parent...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130072.html#130072</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=27322">jamie.townsend</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 13&nbsp;December&nbsp;2007 at 2:44pm<br /><br /><P>You're right that parent paths are best disabled. (Note that parent paths are enabled by default.) <I>Parent paths</I> refers to the ability to use a double period (i.e., ..) in the pathname to refer to a folder above the current folder so that you can move up the folder tree without knowing the folder name or where you are in the hierarchy. </P><DIV>The security risk of parent paths is that intruders can upload and run a script to move up the folder tree. When the script reaches the root, it can move down from there into known folders that might have elevated privileges (e.g., C:\wwwroot\inetpub\scripts, which has Everyone Full Control permission by default, or C:\winnt\system32).</DIV>]]>
   </description>
   <pubDate>Thu, 13 Dec 2007 14:44:05 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130072.html#130072</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : a quick not to parent pathsI am...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130066.html#130066</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=26292">efscl</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 13&nbsp;December&nbsp;2007 at 1:39pm<br /><br />a quick not to parent paths<br><br>I am not sure - but i read often that allowing "Enable parent paths" on IIS is an security hole. When you do he "security check" with the base line security analyzer - this comes up too.<br><br>Borg and audience: Your meanings about that?<br><br><br><br>]]>
   </description>
   <pubDate>Thu, 13 Dec 2007 13:39:11 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130066.html#130066</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : With Access you can often get...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post130000.html#130000</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 11&nbsp;December&nbsp;2007 at 11:12am<br /><br />With Access you can often get away with change the .mdb extension to .asp<br><br>The Access database would still work when connected to by the JET database driver used by Web Wiz Forums, however, because .asp files get parsed by the ASP.DLL by the web server, if a hacker tried to download the file they would just see an error message thrown by the web server and can't actually download the database.<br>]]>
   </description>
   <pubDate>Tue, 11 Dec 2007 11:12:44 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post130000.html#130000</guid>
  </item> 
  <item>
   <title><![CDATA[Disallowed Path Characters : Can&amp;#039;t guarantee it, but I...]]></title>
   <link>https://forums.webwiz.net/disallowed-path-characters_topic24980_post129982.html#129982</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=24799">Jono</a><br /><strong>Subject:</strong> 24980<br /><strong>Posted:</strong> 10&nbsp;December&nbsp;2007 at 10:39pm<br /><br />Can't guarantee it, but I can't see any reason why not. I have used DTS packages on SQL 2000 to read access databases with different extensions and as you have to specify the full path including the extension, it should do.]]>
   </description>
   <pubDate>Mon, 10 Dec 2007 22:39:29 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/disallowed-path-characters_topic24980_post129982.html#129982</guid>
  </item> 
 </channel>
</rss>