Re: [galaxy-dev] redirection vulnerability via URL injection

2013-03-26 Thread Vipin TS
Thanks Dan! I am not sure about the dataset redirecting places other than ucsc and wormbase genome browser. By now, this can be done through Trackster right? Then I will probably disable the external redirecting. any comments/suggestions. thanks, --/Vipin Hi Vipin, Thank you for reporting

Re: [galaxy-dev] redirection vulnerability via URL injection

2013-03-22 Thread Daniel Blankenberg
Hi Vipin, Thank you for reporting this issue. This has to do with the way that the old-style (hard-coded) display applications were modified after introduction of roles to authorize access to an user's datasets that might be permission protected. Ideally, with these old-style applications,

[galaxy-dev] redirection vulnerability via URL injection

2013-03-12 Thread Vipin TS
Hello dev-members, We are trying to place our public Galaxy instancehttp://galaxy.raetschlab.orgin a more secured manner, Currently I am playing with few test cases about the redirection vulnerabilities. The following link uses a URL variable called “redirect_url” to redirect a user to a given