Re: File retrieval vulnerabilities, bugs #1992, #1996

2009-05-22 Thread Martin Dietze
On Thu, May 21, 2009, Igor Vaynberg wrote: we should backport 1992, please open a jira issue to do that. I've already done this. I am currently investigating how I can block particular file types (the hint you gave in your second reply may be helpful here). Once I am confident that my backport

Re: File retrieval vulnerabilities, bugs #1992, #1996

2009-05-22 Thread Martin Dietze
On Thu, May 21, 2009, Igor Vaynberg wrote: we should backport 1992, please open a jira issue to do that. I just appended my backport to #1992, see [1]. I hope that's OK, I can still open a new jira if this is the preferred way to do this. Cheers, Martin [1]

Re: File retrieval vulnerabilities, bugs #1992, #1996

2009-05-21 Thread Igor Vaynberg
we should backport 1992, please open a jira issue to do that. as for access to files, you can see which files we block in org.apache.wicket.markup.html.PackageResourceGuard perhaps we should be more restrictive there. -igor On Tue, May 19, 2009 at 6:15 AM, Martin Dietze d...@fh-wedel.de wrote:

Re: File retrieval vulnerabilities, bugs #1992, #1996

2009-05-21 Thread Igor Vaynberg
and btw, you can install your own more restrictive guard in settings. -igor On Thu, May 21, 2009 at 2:26 PM, Igor Vaynberg igor.vaynb...@gmail.com wrote: we should backport 1992, please open a jira issue to do that. as for access to files, you can see which files we block in

File retrieval vulnerabilities, bugs #1992, #1996

2009-05-19 Thread Martin Dietze
Hi, I just ported the patch fixing #1992 and #1996 back to Wicket 1.3.6. Unfortunately there is still a different issue which may or may not be related to these two. If, for instance, you open the hello world example app and append the string