Re: Malicious bugzilla attachment? [Was: [Bug 63695] session_cookie attribute does not work?]

2019-08-29 Thread Rainer Jung
Am 29.08.2019 um 09:55 schrieb Mark Thomas: That looks suspicious on multiple levels. I'll block the user account and delete the attachment. I'm also tempted to resolve the issue as invalid. Any objections? Thanks for taking actions. I have replied in the ticket, because I think it's a

[Bug 63706] New: Sending http request to https endpoint logs SEVERE in tomcat 9.0.24

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63706 Bug ID: 63706 Summary: Sending http request to https endpoint logs SEVERE in tomcat 9.0.24 Product: Tomcat 9 Version: 9.0.24 Hardware: PC OS: Linux

[Bug 63705] The tomcat pool doesn't register all connection through JMX

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63705 Borja changed: What|Removed |Added OS||Windows 10 -- You are receiving this mail

[Bug 63695] session_cookie attribute does not work?

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63695 --- Comment #3 from kimc@gmail.com --- Created attachment 36741 --> https://bz.apache.org/bugzilla/attachment.cgi?id=36741=edit jk_lb_worker.c modification Showing how I modified the source code -- You are receiving this mail because:

[tomcat] branch master updated: Add properties bundles from the webapp classes

2019-08-29 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new fb63c77 Add properties bundles from the webapp

[Bug 63695] session_cookie attribute does not work?

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63695 --- Comment #5 from Mark Thomas --- The content of attachment 36741 has been deleted for the following reason: Suspected malicious attachment - file type not readable as pptx -- You are receiving this mail because: You are the assignee for

Re: Malicious bugzilla attachment? [Was: [Bug 63695] session_cookie attribute does not work?]

2019-08-29 Thread Mark Thomas
On August 29, 2019 8:52:57 AM UTC, Rainer Jung wrote: >Am 29.08.2019 um 09:55 schrieb Mark Thomas: >> That looks suspicious on multiple levels. >> >> I'll block the user account and delete the attachment. I'm also >tempted >> to resolve the issue as invalid. Any objections? > >Thanks for taking

[Bug 63695] session_cookie attribute does not work?

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63695 --- Comment #4 from kimc@gmail.com --- Comment on attachment 36741 --> https://bz.apache.org/bugzilla/attachment.cgi?id=36741 jk_lb_worker.c modification I have tried to debug 1.2.46 version of tomcat connector and finally I found some

Malicious bugzilla attachment? [Was: [Bug 63695] session_cookie attribute does not work?]

2019-08-29 Thread Rainer Jung
I don't know whether this attachment is just broken or some kind of attack. We might want to delete it if possible. It has suffix .pptx but neither Ooo, nor LibreOffice or Powerpoint show correct content. The file starts with a magic header "NASCA DRM FILE - VER1.00". Regards, Rainer Am

[Bug 63695] session_cookie attribute does not work?

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63695 --- Comment #6 from Rainer Jung --- Note that the docs under http://tomcat.apache.org/connectors-doc/reference/workers.html show that the attribute session_cookie is an LB attribute. You have set it for the two ajp13 workers, but you need to

[Bug 56148] support (multiple) ocsp stapling

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=56148 --- Comment #11 from Mark Thomas --- It is on the TODO list but there are quite a few things ahead of it on the list. -- You are receiving this mail because: You are the assignee for the bug.

Re: Malicious bugzilla attachment? [Was: [Bug 63695] session_cookie attribute does not work?]

2019-08-29 Thread Mark Thomas
That looks suspicious on multiple levels. I'll block the user account and delete the attachment. I'm also tempted to resolve the issue as invalid. Any objections? Mark On 29/08/2019 10:47, Rainer Jung wrote: > I don't know whether this attachment is just broken or some kind of > attack. We

[Bug 63705] New: The tomcat pool doesn't register all connection through JMX

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63705 Bug ID: 63705 Summary: The tomcat pool doesn't register all connection through JMX Product: Tomcat Modules Version: unspecified Hardware: PC Status: NEW

[Bug 63705] The tomcat pool doesn't register all connection through JMX

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63705 Borja changed: What|Removed |Added OS||Windows 10 -- You are receiving this mail

[Bug 63690] [HTTP/2] The socket [*] associated with this connection has been closed.

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63690 --- Comment #14 from Chen Levy --- Created attachment 36744 --> https://bz.apache.org/bugzilla/attachment.cgi?id=36744=edit Simple project demonstrating multipart issue -- You are receiving this mail because: You are the assignee for the

[Bug 63690] [HTTP/2] The socket [*] associated with this connection has been closed.

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63690 --- Comment #15 from Chen Levy --- (In reply to Boris Petrov from comment #13) > Chen Levy, if you could provide a simple sample project that, as you say, > has no external dependencies and breaks with the default Tomcat > configuration on the

[Bug 63706] Sending http request to https endpoint logs SEVERE in tomcat 9.0.24

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63706 Remy Maucherat changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

[tomcat] branch 8.5.x updated: 63706: Avoid NPE accessing https port with plaintext

2019-08-29 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch 8.5.x in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/8.5.x by this push: new df41189 63706: Avoid NPE accessing https port with

[Bug 63695] session_cookie attribute does not work?

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63695 --- Comment #7 from kimc@gmail.com --- Thank you Rainer, I changed my configuration as you adviced like the below. And It works as I intended finally. worker.list=worker_lb worker.worker_lb.type=lb

[tomcat] branch master updated: 63706: Avoid NPE accessing https port with plaintext

2019-08-29 Thread remm
This is an automated email from the ASF dual-hosted git repository. remm pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/tomcat.git The following commit(s) were added to refs/heads/master by this push: new a47066f 63706: Avoid NPE accessing https port

[Bug 63695] session_cookie attribute does not work?

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63695 Rainer Jung changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

buildbot failure in on tomcat-trunk

2019-08-29 Thread buildbot
The Buildbot has detected a new failure on builder tomcat-trunk while building tomcat. Full details are available at: https://ci.apache.org/builders/tomcat-trunk/builds/4572 Buildbot URL: https://ci.apache.org/ Buildslave for this Build: asf946_ubuntu Build Reason: The AnyBranchScheduler

[GitHub] [tomcat] sk8k closed pull request #198: commit desi.test

2019-08-29 Thread GitBox
sk8k closed pull request #198: commit desi.test URL: https://github.com/apache/tomcat/pull/198 This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL

[GitHub] [tomcat] sk8k opened a new pull request #198: commit desi.test

2019-08-29 Thread GitBox
sk8k opened a new pull request #198: commit desi.test URL: https://github.com/apache/tomcat/pull/198 adding desi test. This is an automated message from the Apache Git Service. To respond to the message, please log on to

[GitHub] [tomcat] sk8k commented on issue #199: commit desi.test

2019-08-29 Thread GitBox
sk8k commented on issue #199: commit desi.test URL: https://github.com/apache/tomcat/pull/199#issuecomment-526319367 ccc This is an automated message from the Apache Git Service. To respond to the message, please log on to

[GitHub] [tomcat] sk8k opened a new pull request #199: commit desi.test

2019-08-29 Thread GitBox
sk8k opened a new pull request #199: commit desi.test URL: https://github.com/apache/tomcat/pull/199 c This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the

[GitHub] [tomcat] sk8k closed pull request #199: commit desi.test

2019-08-29 Thread GitBox
sk8k closed pull request #199: commit desi.test URL: https://github.com/apache/tomcat/pull/199 This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL

[Bug 63699] craigwende...@gmail.com

2019-08-29 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=63699 craigwende...@gmail.com changed: What|Removed |Added Version|unspecified |9.0.20