Re: [AOLSERVER] ns_adp_parse ignore safe option

2008-09-05 Thread Alexey Pechnikov
Hello!

В сообщении от Friday 05 September 2008 16:55:50 вы написали:
> Hello Alexei,
>
> If you check the history of that page:
>
> http://dev.aolserver.com/wiki/index.php?title=Ns_adp_parse&diff=5098&oldid=
>2833
>
> the "-safe" part was added on 24 September 2007... which is more recent
> than AOLServer 4.0.
>
> So, if I am not wrong, the "-safe" switch is only available for
> AOLServer 4.5, not 4.0

Thanks!

Best regards, Alexey.


--
AOLserver - http://www.aolserver.com/

To Remove yourself from this list, simply send an email to <[EMAIL PROTECTED]> 
with the
body of "SIGNOFF AOLSERVER" in the email message. You can leave the Subject: 
field of your email blank.


Re: [AOLSERVER] ns_adp_parse ignore safe option

2008-09-05 Thread Juan José del Río
Hello Alexei,

If you check the history of that page:

http://dev.aolserver.com/wiki/index.php?title=Ns_adp_parse&diff=5098&oldid=2833

the "-safe" part was added on 24 September 2007... which is more recent
than AOLServer 4.0.

So, if I am not wrong, the "-safe" switch is only available for
AOLServer 4.5, not 4.0

Regards,

  Juan José


-  
Juan José del Río|  
(+34) 616 512 340|  [EMAIL PROTECTED]


Simple Option S.L.
  Tel: (+34) 951 930 122
  Fax: (+34) 951 930 122
  http://www.simpleoption.com


On Fri, 2008-09-05 at 15:19 +0400, Alexey Pechnikov wrote:
> Hello!
> 
> In page 
> http://dev.aolserver.com/wiki/Ns_adp_parse
> is writed "If you specify the -safe flag, then only registered tags are 
> executed; inline scripts using "<% ... %>" or "<%= ... %>" are ignored."
> 
> I'm try to using 
> ns_adp_parse -file -safe $fname
> and <% ... %> sections are executed! It's very unsecure for me.
> 
> What can I do? I'm using AOLServer 4.0.10-7 from debian etch.
> 
> Best regards, Alexey.
> 
> 
> --
> AOLserver - http://www.aolserver.com/
> 
> To Remove yourself from this list, simply send an email to <[EMAIL 
> PROTECTED]> with the
> body of "SIGNOFF AOLSERVER" in the email message. You can leave the Subject: 
> field of your email blank.
> 
> 


--
AOLserver - http://www.aolserver.com/

To Remove yourself from this list, simply send an email to <[EMAIL PROTECTED]> 
with the
body of "SIGNOFF AOLSERVER" in the email message. You can leave the Subject: 
field of your email blank.


[AOLSERVER] ns_adp_parse ignore safe option

2008-09-05 Thread Alexey Pechnikov
Hello!

In page 
http://dev.aolserver.com/wiki/Ns_adp_parse
is writed "If you specify the -safe flag, then only registered tags are 
executed; inline scripts using "<% ... %>" or "<%= ... %>" are ignored."

I'm try to using 
ns_adp_parse -file -safe $fname
and <% ... %> sections are executed! It's very unsecure for me.

What can I do? I'm using AOLServer 4.0.10-7 from debian etch.

Best regards, Alexey.


--
AOLserver - http://www.aolserver.com/

To Remove yourself from this list, simply send an email to <[EMAIL PROTECTED]> 
with the
body of "SIGNOFF AOLSERVER" in the email message. You can leave the Subject: 
field of your email blank.