Re: [Dspace-tech] Creative Commons license link broken?

2014-05-30 Thread Christian Völker
Hello, Am 25.03.2014 um 18:53 schrieb Bill Tantzen wile...@gmail.com: DSpace 4.1, XMLUI I have enabled the creative commons step for a collection. Everything seems to be working fine on submission. But when I view the full record, in the Files in this item section and in the sub-section

Re: [Dspace-tech] Security vulnerability - Blind SQL injection

2014-05-30 Thread Hilton Gibson
On 30 May 2014 03:32, Koh Kim Boon koh_kim_b...@sp.edu.sg wrote: Recent my dspace server had a security scan and one of the vulnerabilities listed in blind sql injection. ​Hi Koh Can you tell us exactly the nature of the security scan Thanks.​ *Hilton Gibson* Ubuntu Linux Systems

[Dspace-tech] customizing /xmlui/browse?type=subject

2014-05-30 Thread Daniel Scharon
Hello everyone, I would like to edit the way that browse results are displayed when using /xmlui/browse?type=subject. Which part of Mirage theme do I have to modify in order to achieve this? As far as I can see, neither itemSummaryList-DIM nor collectionSummaryList-DIM seem to be the right

Re: [Dspace-tech] Security vulnerability - Blind SQL injection

2014-05-30 Thread Koh Kim Boon
Hi As we are a government related agency, our IT agency does a regular security scan to check for weakness or vulnerabilities. Koh Kim Boon Department of Information and Digital Technology (Library Solutions) 500 Dover Road, Singapore 139651 DID: 67721129 Tel: 67721160 Fax: 61121969 Email:

Re: [Dspace-tech] JAVA_OPTS for cron jobs?

2014-05-30 Thread Alan Orth
Peter, Ahh, that's very interesting. I just looked up the -server flag and it seems on recent Sun/Oracle JVMs -server is implied on 64-bit Linux platforms[0]. It seems my problem was the fact that heuristics used by the OOM killer were killing Tomcat's java instead of whatever filter-media, etc

Re: [Dspace-tech] Security vulnerability - Blind SQL injection

2014-05-30 Thread Pottinger, Hardy J.
Hi, before this conversation goes any further, we have a system to deal with bug reports, and we take them very seriously. Please submit a detailed bug report, including steps to reproduce the error, to https://jira.duraspace.org/browse/DS Thanks! PS, I would be very surprised if any

Re: [Dspace-tech] Security vulnerability - Blind SQL injection

2014-05-30 Thread emilio lorenzo
Hi a couple of weeks ago, we asked about this kind of vulnerabilities in this messge http://dspace.2283337.n4.nabble.com/SQL-injection-attacks-td4673013.html We were notified by our gubernamental IT security agency about the recurrence of this attack (apparently without success) to one of

[Dspace-tech] email configuration

2014-05-30 Thread Fernando Ariel Martinez
Hi, Somebody knows how to disable submissions and registration emails without disabling also change password email? (Google doesn't help.) Any help will be appreciated. Regards. -- --- Lic. Fernando Ariel Martinez

Re: [Dspace-tech] Security vulnerability - Blind SQL injection

2014-05-30 Thread helix84
Hi Koh Kim Boon, by all means, I invite you to submit a Jira bug with the security flag, where more DSpace commiters will take a look at the issue and evaluate it. Here is my investigation: This type of test tests for SQL injection attack by adding an expression to URL parameters, that - if

Re: [Dspace-tech] Security vulnerability - Blind SQL injection

2014-05-30 Thread Tim Donohue
Hi All, First, thanks for the very thorough review, helix84! I've also done a review this morning. As far as I can tell, helix84's conclusions look to be correct. I also haven't been able to find any way to actually perform a successful SQL injection via the reported methods. However, Koh Kim

Re: [Dspace-tech] Creative Commons license link broken?

2014-05-30 Thread Tim Donohue
This Creative Commons license link problem looks to be this one, which is reported in our ticketing system: https://jira.duraspace.org/browse/DS-1354 It's assigned to helix84 (copied in on this email), but it doesn't look to have a fix associated with it, yet. If anyone has a quick fix,

Re: [Dspace-tech] JAVA_OPTS for cron jobs?

2014-05-30 Thread Peter Dietz
My hammer java_opts on our production server, for when some site has crazy big content is to temporarily run it with: JAVA_OPTS=-server -Xms256m -Xmx4g -XX:MaxPermSize=256m We have 64GB ram on our boxes, so we'll survive. Not to derail onto a tangent, but one thing I'd like to see DSpace

Re: [Dspace-tech] email configuration

2014-05-30 Thread Peter Dietz
Hi Fernando, Are you talking about the notification emails the DSpace Administrator receives for submissions and registrations, or the ones that the end-user / submitter receives? You can change who receives the new-user-registration emails by setting: # Recipient for new user registration

Re: [Dspace-tech] Creative Commons license link broken?

2014-05-30 Thread helix84
Hi everyone, I've had that issue assigned for a long time because it has been low priority for me. The comments in DS-1354 and two related issues should help clarify what's wrong and how to fix it. If you have a fix, feel free to submit it. Otherwise I'll get to it someday - no promises when that

Re: [Dspace-tech] JAVA_OPTS for cron jobs?

2014-05-30 Thread Alan Orth
Peter, A queue would be awesome. You're absolutely right regarding the cron jobs; it's almost like you need to set a weekly reminder to go check the execution times of your DSpace maintenance cron jobs to make sure they're all completing and not running at the same time. :) I find that I tweak

Re: [Dspace-tech] customizing /xmlui/browse?type=subject

2014-05-30 Thread Daniel Scharon
Am Freitag, den 30.05.2014, 10:25 +0200 schrieb Daniel Scharon: Hello everyone, I would like to edit the way that browse results are displayed when using /xmlui/browse?type=subject. Which part of Mirage theme do I have to modify in order to achieve this? As far as I can see, neither

Re: [Dspace-tech] Strange issue with DSpace 3.0

2014-05-30 Thread Carlos Walter Blandon Alvarez
Hi helix84. Recently, we have this problem to access to “Control Panel/ DSpace Configuration”. A few weeks ago, this option usually worked and we have not made recent changes to DSpace. org.dspace.app.xmlui.wing.WingInvalidArgument: The 'characters' parameter is required for list items. Java

Re: [Dspace-tech] AIP import error

2014-05-30 Thread Shazia Sathar
Hello Tim, Thank you for the detailed response. I tried the manual migration route and was able to get everything working! Thanks again! Regards, Shazia On May 29, 2014, at 11:04 AM, Tim Donohue tdono...@duraspace.org wrote: Hello Shazia, The error is reporting that one of your items