Re: cocoon-view as possible security problem?

2003-03-21 Thread Sylvain Wallez
Stefano Mazzocchi wrote: Tony Collen wrote: Browsing the livesites, on a whim I tried this URL: http://dir.salon.com/?cocoon-view=content and it worked! Obviously someone deploying Cocoon should be aware that this view is on by default, and may reveal data in your page you might not want. I

Re: cocoon-view as possible security problem?

2003-03-21 Thread Torsten Curdt
By the way, I think there are bigger security problems in cocoon... Don't be shy and speak out loud :) What do have you in mind exactly? -- Torsten

Re: cocoon-view as possible security problem?

2003-03-21 Thread Geoff Howard
At 07:39 AM 3/21/2003, you wrote: By the way, I think there are bigger security problems in cocoon... Don't be shy and speak out loud :) What do have you in mind exactly? -- Torsten Sorry - wasn't being shy, just trying to be quick and didn't have time to get fully into that fully right now (nor

Re: cocoon-view as possible security problem?

2003-03-21 Thread Steven Noels
On 21/03/2003 13:57 Geoff Howard wrote: OK, gotta get back to work - I'm in the middle of a launch. Be careful, rockets are nasty things these days. /Steven -- Steven Noelshttp://outerthought.org/ Outerthought - Open Source, Java XML Competence Support Center Read my

Re: cocoon-view as possible security problem?

2003-03-21 Thread Steven Noels
On 21/03/2003 13:57 Geoff Howard wrote: Also, is cocoon-reload still enabled by default? seems a wget in a loop with ?cocoon-reload=true could put a site in a world of hurt... (by the way, last time I checked Jetty/Cocoon cvs is barfing on that..) ... and from the difference in speed between

Re: cocoon-view as possible security problem?

2003-03-21 Thread Pier Fumagalli
Steven Noels [EMAIL PROTECTED] wrote: On 21/03/2003 13:57 Geoff Howard wrote: Also, is cocoon-reload still enabled by default? seems a wget in a loop with ?cocoon-reload=true could put a site in a world of hurt... (by the way, last time I checked Jetty/Cocoon cvs is barfing on that..)

Re: cocoon-view as possible security problem?

2003-03-21 Thread Stefano Mazzocchi
Geoff Howard wrote: By the way, I think there are bigger security problems in cocoon... Like what? (not being arrogant or defensive, just curious... damn email communication sometimes coveys the wrong tone) Stefano.

Re: cocoon-view as possible security problem?

2003-03-21 Thread Vadim Gritsenko
Steven Noels wrote: On 21/03/2003 13:57 Geoff Howard wrote: Also, is cocoon-reload still enabled by default? seems a wget in a loop with ?cocoon-reload=true could put a site in a world of hurt... (by the way, last time I checked Jetty/Cocoon cvs is barfing on that..) ... and from the

Re: cocoon-view as possible security problem?

2003-03-21 Thread Vadim Gritsenko
Geoff Howard wrote: By the way, I think there are bigger security problems in cocoon... snip/ Also, is cocoon-reload still enabled by default? seems a wget in a loop with ?cocoon-reload=true could put a site in a world of hurt... (by the way, last time I checked Jetty/Cocoon cvs is barfing

Re: cocoon-view as possible security problem?

2003-03-21 Thread Geoff Howard
At 08:33 AM 3/21/2003, you wrote: Geoff Howard wrote: By the way, I think there are bigger security problems in cocoon... snip/ Also, is cocoon-reload still enabled by default? seems a wget in a loop with ?cocoon-reload=true could put a site in a world of hurt... (by the way, last time I

Re: cocoon-view as possible security problem?

2003-03-21 Thread Geoff Howard
At 08:24 AM 3/21/2003, you wrote: Geoff Howard wrote: By the way, I think there are bigger security problems in cocoon... Like what? (not being arrogant or defensive, just curious... damn email communication sometimes coveys the wrong tone) Stefano. You've probably seen my other email by now,

Re: cocoon-view as possible security problem?

2003-03-21 Thread Tony Collen
On Fri, 21 Mar 2003, Geoff Howard wrote: Is it? With in-memory upload you can get to OutOfMemory exceptions and potentially corrupt cocoon instance. With file uploads, you can create 100Mb file systems which you can fill up but you won't disturb functionality of the server. I don't see how

Re: cocoon-view as possible security problem?

2003-03-21 Thread Vadim Gritsenko
Tony Collen wrote: On Fri, 21 Mar 2003, Geoff Howard wrote: Is it? With in-memory upload you can get to OutOfMemory exceptions and potentially corrupt cocoon instance. With file uploads, you can create 100Mb file systems which you can fill up but you won't disturb functionality of the server.

Re: cocoon-view as possible security problem?

2003-03-21 Thread Geoff Howard
At 01:52 PM 3/21/2003, you wrote: On Fri, 21 Mar 2003, Geoff Howard wrote: Is it? With in-memory upload you can get to OutOfMemory exceptions and potentially corrupt cocoon instance. With file uploads, you can create 100Mb file systems which you can fill up but you won't disturb functionality

Re: cocoon-view as possible security problem?

2003-03-21 Thread Geoff Howard
At 03:19 AM 3/21/2003, you wrote: Stefano Mazzocchi wrote: Tony Collen wrote: Browsing the livesites, on a whim I tried this URL: http://dir.salon.com/?cocoon-view=content and it worked! Obviously someone deploying Cocoon should be aware that this view is on by default, and may reveal data in

Re: cocoon-view as possible security problem?

2003-03-21 Thread Tony Collen
On Fri, 21 Mar 2003, Geoff Howard wrote: multiple-snippage/ So, at the end, I would do: 1) turn off views from the default sitemap. NOTE: this will turn off the ability to make static snapshots of your webapp from the cocoon CLI! Well, this is obviously not good for us... so... 2) write

cocoon-view as possible security problem?

2003-03-20 Thread Tony Collen
Browsing the livesites, on a whim I tried this URL: http://dir.salon.com/?cocoon-view=content and it worked! Obviously someone deploying Cocoon should be aware that this view is on by default, and may reveal data in your page you might not want. I have yet to see bad data get exposed, but

Re: cocoon-view as possible security problem?

2003-03-20 Thread Stefano Mazzocchi
Tony Collen wrote: Browsing the livesites, on a whim I tried this URL: http://dir.salon.com/?cocoon-view=content and it worked! Obviously someone deploying Cocoon should be aware that this view is on by default, and may reveal data in your page you might not want. I have yet to see bad data