|
I don't know what you mean by "minor" issue.. but after
no answers except asking us to send what we inputed into our
cgi from support i tried tracking down the problem myself, and now
have somewhat an idea what the problem is(was??)
first of even if all the contact info is all < 127 ASCII
this problem occured when our customers tried registering domains with a
previous profile being a multilingual domain. (i sent this info to support)
b.t.w. we know this because we log all(except password info) cgi input and
output through our reg_system.cgi
this, in my opinion is a bug whichever way you look at it, and
should be fixed pronto, maybe already fixed?
note: we have never allowed non-english characters in our
contact info when registering domains as we have always feared it would cause
problems in the future
second of all, after analyzing opensrs reg_system.cgi, we
found out that the CGI automatically sends all form input to opensrs, which
means if we create a new field for cc processing and put korean characters in
it, like the domain name, opensrs spits out an error. it used to NOT(spit out
the error) do that before opensrs servers moved
personally i think it is real bad security that all form input
is automatically parsed and sent off to opensrs as this is asking for hackers
to try to screw up opensrs resellers by sending manipulated form
values. not sure but i think i noticed a "security" change in the source from
2.41 to 2.46 because of this behavior.
I would appreciate a reply whether the first is fixed and
whether the second has changed.. that being non opensrs fields being screened
for non < 127 ASCII characters.
lastly i am VERY INTERESTED in knowing if the opensrs codebase
is going to complety move to the opensrs-sf code or if the current code is going
to be developed together in parallel. personally i like the current style of
coding compared to opensrs-sf. support once told me it's opensrs-sf is going to
replace the current code, and now i hear not so sure.
thanks,
GaGaDomain
Park Yong Gu
(mail: [EMAIL PROTECTED] MSN ID: [EMAIL PROTECTED])
|
- opensrs errors for multilingual domains ???
- RE: opensrs errors for multilingual domains Charles Daminato
- Re: opensrs errors for multilingual domains Jose Luis Moya
- RE: opensrs errors for multilingual domains Charles Daminato
- Re: opensrs errors for multilingual doma... Alex Brecher
- Re: opensrs errors for multilingual... Charles Daminato
- Re: opensrs errors for multilin... Alex Brecher
- Re: opensrs errors for mult... Charles Daminato
- Re: opensrs errors for mult... Alex Brecher
- RE: opensrs errors for multilingual domains Charles Daminato
- RE: opensrs errors for multilingual domains GaGaDomain
- RE: opensrs errors for multilingual domains Charles Daminato
