Sorry its been so long Zoli, this email got lots in the pile of
"enhancement" emails I seem to get :)

I was not stating that service mapping was insecure, what I was
suggesting is that fluorine should be default block all services that
are not explicitly names in a service mapping configuration.  Developer,
being developers often forget things, and before you know it, someone
will have figured out the services in a developers page and be using
services that were not intended for public consumption to destroy data.
I do software security for a living and file holes in software all the
time from seasoned developers.

I'd love to see a service mapping section for Fluorine, I'm using
Fluorine right now on 2 projects.
Grant.

 
Zoli said :
...I cannot see why service mapping is considered secure (?)


_______________________________________________
osflash mailing list
[email protected]
http://osflash.org/mailman/listinfo/osflash_osflash.org

Reply via email to