DO NOT REPLY [Bug 23471] New: - No Java compiler was found to compile the generated source for the JSP

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23471. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat/proposals/JmxSupport/WEB-INF/classes/org/apache/tomcat/modules/config MxInterceptor.java DynamicMBeanProxy.java

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:38:10 Modified:proposals/JmxSupport/WEB-INF/classes/org/apache/tomcat/modules/config MxInterceptor.java DynamicMBeanProxy.java Log: Add JRMP support if we ever use this Interceptor Revision ChangesPath 1.2 +127 -53

cvs commit: jakarta-tomcat/src/examples/WEB-INF/classes/sessions DummyCart.java

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:39:50 Modified: proposals/Log4jHelper/WEB-INF/classes/org/apache/tomcat/modules/loggers/log4j Log4jHelper.java CRS.java src/examples/WEB-INF/classes/examples FooTagExtraInfo.java LogTag.java

cvs commit: jakarta-tomcat/proposals/build2/WEB-INF/src AntTEI.java AntServletLogger.java AntTarget.java AntTag.java AntProperty.java

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:40:14 Modified:proposals/build2/WEB-INF/src AntTEI.java AntServletLogger.java AntTarget.java AntTag.java AntProperty.java Log: More imports cleaned (the wildcard for example) Revision ChangesPath 1.2

cvs commit: jakarta-tomcat/src/share/org/apache/tomcat/resources LocalStrings_fr.properties

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:41:11 Modified:src/share/org/apache/tomcat/resources LocalStrings_fr.properties Log: Fix translation Revision ChangesPath 1.7 +2 -2 jakarta-tomcat/src/share/org/apache/tomcat/resources/LocalStrings_fr.properties

cvs commit: jakarta-tomcat/src/doc AJPv13.html serverxml.html

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:42:59 Modified:src/doc AJPv13.html serverxml.html Log: Update ajp13 doc (ping/pong added), and also MxInterceptor (added jrmp) Revision ChangesPath 1.7 +11 -0 jakarta-tomcat/src/doc/AJPv13.html Index: AJPv13.html

cvs commit: jakarta-tomcat/src/native/mod_jk OBSOLETE.txt

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:43:33 Added: src/native/mod_jk OBSOLETE.txt Log: A note to warn users that this version of mod_jk is obsolete Revision ChangesPath 1.1 jakarta-tomcat/src/native/mod_jk/OBSOLETE.txt Index: OBSOLETE.txt

cvs commit: jakarta-tomcat/src/tests/share/gtest GTest.java

2003-09-29 Thread hgomez
hgomez 2003/09/29 00:43:40 Modified:src/tests/share/gtest GTest.java Log: More imports cleaned (the wildcard for example) Revision ChangesPath 1.4 +11 -4 jakarta-tomcat/src/tests/share/gtest/GTest.java Index: GTest.java

DO NOT REPLY [Bug 12428] - request.getUserPrincipal(): Misinterpretation of specification?

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=12428. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-connectors/procrun - New directory

2003-09-29 Thread mturk
mturk 2003/09/29 01:59:43 jakarta-tomcat-connectors/procrun - New directory - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

cvs commit: jakarta-tomcat-connectors/procrun extend.h icoi.ico icos.ico icow.ico splash.bmp tomcat.c tomcat.dsp tomcat.dsw tomcat.rc tomcatp.ico tomcatr.ico tomcats.ico

2003-09-29 Thread mturk
mturk 2003/09/29 02:01:40 Added: procrun extend.h icoi.ico icos.ico icow.ico splash.bmp tomcat.c tomcat.dsp tomcat.dsw tomcat.rc tomcatp.ico tomcatr.ico tomcats.ico Log: Add the procrun tomcat extension to the j-t-c. Revision

cvs commit: jakarta-tomcat-connectors/procrun/bin - New directory

2003-09-29 Thread mturk
mturk 2003/09/29 02:03:22 jakarta-tomcat-connectors/procrun/bin - New directory - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

cvs commit: jakarta-tomcat-connectors/procrun/bin tomcat.exe tomcatw.exe

2003-09-29 Thread mturk
mturk 2003/09/29 02:04:33 Added: procrun/bin tomcat.exe tomcatw.exe Log: Add the tomcat and tomcatw binaries. Revision ChangesPath 1.1 jakarta-tomcat-connectors/procrun/bin/tomcat.exe Binary file 1.1

cvs commit: jakarta-tomcat-connectors/procrun README.txt

2003-09-29 Thread mturk
mturk 2003/09/29 02:06:33 Added: procrun README.txt Log: Simple readme for build instructions. Revision ChangesPath 1.1 jakarta-tomcat-connectors/procrun/README.txt Index: README.txt

DO NOT REPLY [Bug 15735] - Misspelling in french

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=15735. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 18939] - Adding a New Mobile Device

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=18939. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 8155] - Tomcat from RPM doesn't do logrotate

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=8155. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 8155] - Tomcat from RPM doesn't do logrotate

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=8155. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 4893] - Tomcat dies with following error..

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=4893. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23477] New: - the admin and manager webapps is not available when host appbase is out of catalina home.

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23477. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23478] New: - StringIndexOutOfBoundsException with an empty jsp file name

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23478. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23477] - the admin and manager webapps is not available when host appbase is out of catalina home.

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23477. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

TC 3.3.2

2003-09-29 Thread Henri Gomez
Hi to all, I commited the last part of clean imports and started to take a look at bugzilla where many reports seems still open. What's the strategy now ? Should we close those which seems invalid ? - To unsubscribe, e-mail:

cvs commit: jakarta-tomcat-catalina/catalina/src/bin catalina.bat catalina.xml

2003-09-29 Thread remm
remm2003/09/29 03:27:20 Modified:catalina/src/bin catalina.bat catalina.xml Log: - Set -Dsun.io.useCanonCaches=false for Windows. This decreases startup performance significantly, but is needed for now (since Sun doesn't seem to be willing to fix the bug in a timely

cvs commit: jakarta-tomcat-5 build.properties.default build.xml tomcat.nsi

2003-09-29 Thread remm
remm2003/09/29 03:27:40 Modified:.build.properties.default build.xml tomcat.nsi Log: - Set -Dsun.io.useCanonCaches=false for Windows. This decreases startup performance significantly, but is needed for now (since Sun doesn't seem to be willing to fix the bug in a

Re: cvs commit: jakarta-tomcat-5 build.properties.default build.xml tomcat.nsi

2003-09-29 Thread Remy Maucherat
[EMAIL PROTECTED] wrote: remm2003/09/29 03:27:40 Modified:.build.properties.default build.xml tomcat.nsi Log: - Set -Dsun.io.useCanonCaches=false for Windows. This decreases startup performance significantly, but is needed for now (since Sun doesn't seem to be

DO NOT REPLY [Bug 23482] New: - Sequential stopping and re-starting of web application leads to out of memory exception

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23482. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23482] - Sequential stopping and re-starting of web application leads to out of memory exception

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23482. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23483] New: - More than 42 channels causes JK2 to segfault

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23483. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Glenn Nielsen
As part of the mod_jk 1.2.5 release I promised to move the JTC download to www.apache.org/dist so that the downloads can be mirrored. Here are the changes I propose to make as I set this up. First, here is the directory layout for mirrored downloads at

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Henri Gomez
Glenn Nielsen a écrit : As part of the mod_jk 1.2.5 release I promised to move the JTC download to www.apache.org/dist so that the downloads can be mirrored. Here are the changes I propose to make as I set this up. First, here is the directory layout for mirrored downloads at

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Remy Maucherat
Glenn Nielsen wrote: 1. Coyote - /www/jakarta.apache.org/builds/jakarta-tomcat-connectors/coyote/release/ This contains 9 coyote connector beta release and one release candidate. Do we need to keep these? If not, since coyote comes with the Tomcat releases, why not completely remove coyote

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread jean-frederic clere
Henri Gomez wrote: Glenn Nielsen a écrit : As part of the mod_jk 1.2.5 release I promised to move the JTC download to www.apache.org/dist so that the downloads can be mirrored. Here are the changes I propose to make as I set this up. First, here is the directory layout for mirrored downloads

DO NOT REPLY [Bug 12428] - request.getUserPrincipal(): Misinterpretation of specification?

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=12428. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-5 tomcat.nsi

2003-09-29 Thread remm
remm2003/09/29 06:16:08 Modified:.tomcat.nsi Log: - Group should actually not be used. I misunderstood Mladen's instructions. Revision ChangesPath 1.36 +2 -2 jakarta-tomcat-5/tomcat.nsi Index: tomcat.nsi

New tags

2003-09-29 Thread Remy Maucherat
I propose putting new tags (hopefully on Friday, sometimes next week otherwise): - 5.0.13 (this could be a release candidate beta :)) - 4.1.28 (connector fixes, reloading fix, other fixes) Remy - To unsubscribe, e-mail:

DO NOT REPLY [Bug 23489] New: - Problems when posting Unicode characters to a servlet

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23489. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23490] New: - [PATCH] ant task I18N for manager webapp

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23490. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

RE: TC 3.3.2

2003-09-29 Thread Larry Isaacs
-Original Message- From: Henri Gomez [mailto:[EMAIL PROTECTED] Sent: Monday, September 29, 2003 5:56 AM To: Tomcat Developers List Subject: TC 3.3.2 Hi to all, I commited the last part of clean imports and started to take a look at bugzilla where many reports seems still

Re: TC 3.3.2

2003-09-29 Thread Bill Barker
- Original Message - From: Henri Gomez [EMAIL PROTECTED] To: Tomcat Developers List [EMAIL PROTECTED] Sent: Monday, September 29, 2003 2:55 AM Subject: TC 3.3.2 Hi to all, I commited the last part of clean imports and started to take a look at bugzilla where many reports seems still

TC4.1: StandardWrapperValve infinite recursion

2003-09-29 Thread Urban Widmark
Hello I have a question regarding the status of Bug# 19312 (and 21834) http://marc.theaimsgroup.com/?l=tomcat-devm=105170151514979w=2 It was reported against 4.1.24 but is not fixed in 4.1.27 nor is it fixed in the jakarta-tomcat-4.0 CVS tree. Someone was working on it in April but nothing has

DO NOT REPLY [Bug 23390] - Invalid direct reference to form

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23390. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread David Rees
Anyone know how serious this is? It also appears to affect Tomcat 4.1.27 when using mod_jk as well. Below is a sample trace of a HTTP session. -Dave telnet localhost 8080 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. GET /666%0a%0ascriptalert(asdf);/script666.jsp

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Shapira, Yoav
Howdy, I'm not a big security buff, but three things come to mind: - The original post with the exploit is more than a year old, yet we haven't heard anything about this actually used maliciously -- how come? - Is it really a vulnerability? What can you get from this exploit? All I see is tomcat

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Glenn Nielsen
Henri Gomez wrote: Glenn Nielsen a écrit : As part of the mod_jk 1.2.5 release I promised to move the JTC download to www.apache.org/dist so that the downloads can be mirrored. Here are the changes I propose to make as I set this up. First, here is the directory layout for mirrored downloads

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Glenn Nielsen
Remy Maucherat wrote: Glenn Nielsen wrote: 1. Coyote - /www/jakarta.apache.org/builds/jakarta-tomcat-connectors/coyote/release/ This contains 9 coyote connector beta release and one release candidate. Do we need to keep these? If not, since coyote comes with the Tomcat releases, why not

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Glenn Nielsen
jean-frederic clere wrote: Henri Gomez wrote: Glenn Nielsen a écrit : As part of the mod_jk 1.2.5 release I promised to move the JTC download to www.apache.org/dist so that the downloads can be mirrored. Here are the changes I propose to make as I set this up. First, here is the directory

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread David Rees
On Mon, September 29, 2003 1at 1:57 am, Shapira, Yoav sent the following I'm not a big security buff, but three things come to mind: - The original post with the exploit is more than a year old, yet we haven't heard anything about this actually used maliciously -- how come? Can't answer this

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Bill Barker
Remy has already patched the HTTP Connector for this one (both Tomcat 45). I believe that the patch still needs to be ported to the JK2 Connector. - Original Message - From: Shapira, Yoav [EMAIL PROTECTED] To: Tomcat Developers List [EMAIL PROTECTED] Sent: Monday, September 29, 2003

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread David Rees
On Mon, September 29, 2003 1at 2:32 pm, Bill Barker sent the following Remy has already patched the HTTP Connector for this one (both Tomcat 45). I believe that the patch still needs to be ported to the JK2 Connector. Thanks for the update, Bill. Hope to see Tomcat 4.1.28 out soon, look like

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Shapira, Yoav
Howdy, This is interesting, hopefully you won't mind educating me a bit further... - Is it really a vulnerability? What can you get from this exploit? You can hijack the user's session or steal information from a user's cookie pretty easily with a XSS flaw such as this one. How would you

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Chad Johnson
Hey, Just thought I'd pop in on this one. Fairly standard XSS attack: -Insert/execute javascript to pull some key piece of data (ex. value of the jsessionid cookie) -This same bit of javascript will then make a http request (through one several means) to an attackers website which involves

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread David Rees
On Mon, September 29, 2003 1at 2:34 pm, Shapira, Yoav sent the following Howdy, This is interesting, hopefully you won't mind educating me a bit further... Not at all, but keep in mind I haven't studied all that much myself... ;-) - Is it really a vulnerability? What can you get from this

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Shapira, Yoav
Howdy, OK, makes sense. Thanks for the examples! Yoav Shapira Millennium ChemInformatics -Original Message- From: David Rees [mailto:[EMAIL PROTECTED] Sent: Monday, September 29, 2003 3:50 PM To: Tomcat Developers List Subject: RE: Jakarta Tomcat 4.1 XSS vulnerability On Mon,

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Remy Maucherat
David Rees wrote: Anyone know how serious this is? Lol. If you're affected by XSS, then you have a problem (no site in the world deserves any privilege: *all* need javascript blocking these days). It also appears to affect Tomcat 4.1.27 when using mod_jk as well. Below is a sample trace of a

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Bill Barker
- Original Message - From: David Rees [EMAIL PROTECTED] To: Tomcat Developers List [EMAIL PROTECTED] Sent: Monday, September 29, 2003 12:33 PM Subject: Re: Jakarta Tomcat 4.1 XSS vulnerability On Mon, September 29, 2003 1at 2:32 pm, Bill Barker sent the following Remy has already

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Tim Funk
Actually this could be issue on a poorly configured site where the admin does not override the default error pages. It would make it very easy to steal someone's cookies or session. So while might be an issue (I personally haven't checked), its not an issue if the admin configures custom error

DO NOT REPLY [Bug 23502] New: - Incorrect path in generated SMAP file entries

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23502. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

RE: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread David Rees
On Mon, September 29, 2003 1at 2:49 pm, Shapira, Yoav sent the following Howdy, OK, makes sense. Thanks for the examples! Glad I could help. Hopefully you (and others) can use this information while designing web applications to avoid similar XSS issues in the future even if they are

Re: Jakarta Tomcat 4.1 XSS vulnerability

2003-09-29 Thread Jeff Tulley
I've found a very good explanation of XSS: http://www.spidynamics.com/whitepapers/SPIcross-sitescripting.pdf Jeff Tulley ([EMAIL PROTECTED]) (801)861-5322 Novell, Inc., The Leading Provider of Net Business Solutions http://www.novell.com [EMAIL PROTECTED] 9/29/03 2:26:54 PM Actually this

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Joseph Shraibman
./configure -with-apxs=/usr/local/apache2/bin/apxsGlenn Nielsen wrote: As part of the mod_jk 1.2.5 release I promised to move the JTC download to BTW you forgot to generate a configure file for the release, users will have to run buildconf.sh

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Glenn Nielsen
Joseph Shraibman wrote: ./configure -with-apxs=/usr/local/apache2/bin/apxsGlenn Nielsen wrote: As part of the mod_jk 1.2.5 release I promised to move the JTC download to BTW you forgot to generate a configure file for the release, users will have to run buildconf.sh Running buildconf.sh is

DO NOT REPLY [Bug 23471] - No Java compiler was found to compile the generated source for the JSP

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23471. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

[PATCH] ./jk/native/apache-2.0/mod_jk.c compile with Apache 2.1

2003-09-29 Thread Günter Knauf
Hi, with Apache 2.1 and APR 1.0 seems that apu_compat.h is removed (see APR-util Changes); attached a patch which works for me with both APR 0.9.4 and APR 1.0.0 Guenter. --- mod_jk.c.orig Sat Sep 06 17:37:20 2003 +++ mod_jk.cTue Sep 30 03:57:24 2003 @@ -67,7 +67,6 @@ * mod_jk: keeps

DO NOT REPLY [Bug 23316] - Oracle JDBCRealms failed after tns listener restart.

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23316. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23506] New: - After recompiling servlet source, 503 error occured

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23506. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23506] - After recompiling servlet source, 503 error occured

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23506. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-connectors/jk/xdocs/jk aphowto.xml

2003-09-29 Thread glenn
glenn 2003/09/29 20:09:06 Modified:jk/xdocs/jk aphowto.xml Log: Update download links to use jakarta mirror cgi Revision ChangesPath 1.24 +7 -23 jakarta-tomcat-connectors/jk/xdocs/jk/aphowto.xml Index: aphowto.xml

DO NOT REPLY [Bug 23477] - the admin and manager webapps is not available when host appbase is out of catalina home.

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23477. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-connectors/jk HOWTO-RELEASE

2003-09-29 Thread glenn
glenn 2003/09/29 21:15:52 Modified:jk HOWTO-RELEASE Log: Update docs for packaging releases and mirror downloads Revision ChangesPath 1.8 +28 -32jakarta-tomcat-connectors/jk/HOWTO-RELEASE Index: HOWTO-RELEASE

cvs commit: jakarta-tomcat-connectors/jk/java/org/apache/jk/server JkCoyoteHandler.java

2003-09-29 Thread billbarker
billbarker2003/09/29 21:17:37 Modified:jk/java/org/apache/jk/server JkCoyoteHandler.java Log: Remove nls from the status line. Revision ChangesPath 1.46 +5 -1 jakarta-tomcat-connectors/jk/java/org/apache/jk/server/JkCoyoteHandler.java Index:

cvs commit: jakarta-tomcat-connectors/jk/java/org/apache/jk/server JkCoyoteHandler.java

2003-09-29 Thread billbarker
billbarker2003/09/29 21:18:45 Modified:jk/java/org/apache/jk/server Tag: coyote_10 JkCoyoteHandler.java Log: port patch. Revision ChangesPath No revision No revision 1.32.2.4 +5 -1

Re: mod_jk release packaging and connector download move to www.apache.org/dist mirror and archive.apache.org

2003-09-29 Thread Glenn Nielsen
I have completed most of the below. The directory layout is setup in /www/www.apache.org/dist/jakarta/tomcat-connectors and /www/archive.apache.org/dist/jakarta/tomcat-connectors . The old coyote beta and milestone releases have been removed. The webapp releases have been moved to the archive.

cvs commit: jakarta-tomcat/src/share/org/apache/jasper/compiler JasperMangler.java

2003-09-29 Thread billbarker
billbarker2003/09/29 21:49:59 Modified:src/share/org/apache/jasper/compiler JasperMangler.java Log: Fix problem with empty JSP file. Fix for bug #23478. Reported By: Jens [EMAIL PROTECTED] Revision ChangesPath 1.12 +1 -1

DO NOT REPLY [Bug 23477] - the admin and manager webapps is not available when host appbase is out of catalina home.

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23477. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 23478] - StringIndexOutOfBoundsException with an empty jsp file name

2003-09-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=23478. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-connectors/http11/src/java/org/apache/coyote/http11 InternalOutputBuffer.java

2003-09-29 Thread billbarker
billbarker2003/09/29 22:38:15 Modified:http11/src/java/org/apache/coyote/http11 Tag: coyote_10 InternalOutputBuffer.java Log: Port the no-nl patch from the Head branch. Revision ChangesPath No revision No

cvs commit: jakarta-tomcat-connectors/http11/src/java/org/apache/coyote/http11 InternalOutputBuffer.java

2003-09-29 Thread billbarker
billbarker2003/09/29 22:40:27 Modified:http11/src/java/org/apache/coyote/http11 Tag: coyote_10 InternalOutputBuffer.java Log: Trying to escape the dreaded tab-police. Revision ChangesPath No revision No