Re: [Zope] Script (Python) insecure ?

2008-08-16 Thread Dieter Maurer
M.-A. Lemburg wrote at 2008-8-12 13:41 +0200: ... While I have not yet been able to break out of the restricted environment without help from installed products, there are a few denial-of-service attacks which can easily be deployed on sites allowing adding Python Scripts to a user folder: 1.

Re: [Zope] Persistent Mapping error with TinyTablePlus.

2008-08-16 Thread Dieter Maurer
Ignacio Valdes wrote at 2008-8-12 13:30 -0500: Hi Chris, When I try to change a Squishdot rightbox_items title or even not change anything and try to save it out I get this error thrown: Site Error An error was encountered while publishing this resource. NameError Sorry, a site error occurred.

Re: [Zope] ZEO clusters on a single box

2008-08-16 Thread Dieter Maurer
Jean Jordaan wrote at 2008-8-13 12:26 +0700: We have a server running many ZEO clusters (many more than the number of CPUs, of course). Each cluster consists of a master and two clients. Would it make sense to run both clients and spread requests across them? Usually, this would make sense when

Re: [Zope] uncataloging

2008-08-16 Thread Dieter Maurer
Darryl Caldwell wrote at 2008-8-13 19:49 -0800: ... I have looked at the source of Catalog.py but am still confused about what parameters I need to uncatalog an object. Is the uid the same as the object id? No. The uid that you must pass to uncatalog_object is the same one that has been passed

Re: [Zope] Searching for a range or a value

2008-08-16 Thread Dieter Maurer
Andrea Ratto wrote at 2008-8-14 10:25 +0200: I am trying to search for items with an attribute (a price) in a defined range, but I also need to match those which have None in that attribute. The index is a FieldIndex, Zope is at version 2.10 Is there any way to do that without doing two

Re: [Zope] uncataloging

2008-08-16 Thread Jens Vagelpohl
On Aug 16, 2008, at 11:06 , Dieter Maurer wrote: The easiest way to determine the uid is probably to locate the object via a catalog search. You will get a catalog proxy for the object, often also called brain. This proxy has the method getPath() which returns the object's uid -- don't

Re: [Zope] Script (Python) insecure ?

2008-08-16 Thread M.-A. Lemburg
On 2008-08-16 08:00, Dieter Maurer wrote: M.-A. Lemburg wrote at 2008-8-12 13:41 +0200: ... While I have not yet been able to break out of the restricted environment without help from installed products, there are a few denial-of-service attacks which can easily be deployed on sites allowing

Re: [Zope] Script (Python) insecure ?

2008-08-16 Thread Andreas Jung
--On 16. August 2008 13:11:13 +0200 M.-A. Lemburg [EMAIL PROTECTED] wrote: In my experience, attempts to create a sandbox that protects sufficiently against unwanted resource usage are either too restrictive and slow to make them useful or have problems preventing DOS attacks. I think you

Re: [Zope] Script (Python) insecure ?

2008-08-16 Thread M.-A. Lemburg
On 2008-08-16 13:39, Andreas Jung wrote: --On 16. August 2008 13:11:13 +0200 M.-A. Lemburg [EMAIL PROTECTED] wrote: In my experience, attempts to create a sandbox that protects sufficiently against unwanted resource usage are either too restrictive and slow to make them useful or have

Re: [Zope] Script (Python) insecure ?

2008-08-16 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 M.-A. Lemburg wrote: On 2008-08-16 08:00, Dieter Maurer wrote: M.-A. Lemburg wrote at 2008-8-12 13:41 +0200: ... While I have not yet been able to break out of the restricted environment without help from installed products, there are a few

[Zope] PROXISOFT Info Service

2008-08-16 Thread info
Sehr geehrte Damen und Herren, Sie haben eine Email an die Adresse [EMAIL PROTECTED] gesendet. Wegen massiven Spam Atacken wird diese Adresse nicht mehr betrieben. Um Kontakt mit PROXISOFT auftzunehmen, rufen Sie bitte unsere Homepage www.proxisoft.de in Ihrem Browser auf. Viele Grüße - Ihr

Re: [Zope] Script (Python) insecure ?

2008-08-16 Thread Chris Withers
Andreas Jung wrote: BTW: The reason why I had a look at these was that Chris Withers mentioned at EuroPython that they are currently causing delays in the Python 2.5 adoption (or at least are one of the reasons for them). Is Chris' talk somewhere online? Sorry, they were just quick

[Zope-Checkins] SVN: Zope/branches/2.11/lib/python/Products/PageTemplates/ Launchpad #254570:

2008-08-16 Thread Andreas Jung
Log message for revision 89904: Launchpad #254570: the PreferredCharset resolver now deals with situations where 'context' has no REQUEST attribute Changed: U Zope/branches/2.11/lib/python/Products/PageTemplates/tests/testZopePageTemplate.py U

[Zope-dev] Zope Tests: 4 OK, 1 Unknown

2008-08-16 Thread Zope Tests Summarizer
Summary of messages to the zope-tests list. Period Fri Aug 15 11:00:00 2008 UTC to Sat Aug 16 11:00:00 2008 UTC. There were 5 messages: 5 from Zope Tests. Unknown --- Subject: UNKNOWN : Zope-2.8 Python-2.3.6 : Linux From: Zope Tests Date: Fri Aug 15 20:40:07 EDT 2008 URL:

Re: [Zope-dev] Zope Tests: 4 OK, 1 Unknown

2008-08-16 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Zope Tests Summarizer wrote: Summary of messages to the zope-tests list. Period Fri Aug 15 11:00:00 2008 UTC to Sat Aug 16 11:00:00 2008 UTC. There were 5 messages: 5 from Zope Tests. Unknown --- Subject: UNKNOWN : Zope-2.8

Re: [Zope-dev] Zope Tests: 4 OK, 1 Unknown

2008-08-16 Thread Philipp von Weitershausen
Tres Seaver wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Zope Tests Summarizer wrote: Summary of messages to the zope-tests list. Period Fri Aug 15 11:00:00 2008 UTC to Sat Aug 16 11:00:00 2008 UTC. There were 5 messages: 5 from Zope Tests. Unknown --- Subject: UNKNOWN :

Re: [Zope-dev] Zope Tests: 4 OK, 1 Unknown

2008-08-16 Thread Andreas Jung
--On 16. August 2008 17:18:56 +0200 Philipp von Weitershausen [EMAIL PROTECTED] wrote: Tres Seaver wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Zope Tests Summarizer wrote: Summary of messages to the zope-tests list. Period Fri Aug 15 11:00:00 2008 UTC to Sat Aug 16 11:00:00 2008

Re: [Zope-dev] zope.testrunner test failures, remaining ones not windows specific ; -)

2008-08-16 Thread Chris Withers
Marius Gedminas wrote: On Tue, Aug 12, 2008 at 09:17:39PM +0100, Chris Withers wrote: I could have sworn I reported this before but couldn't find anything in the archives so apologies if I have posted this before... I have a feeling of deja vu about this... Indeed ;-) File