Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-07 Thread Dieter Maurer
Rossen Raykov writes: * the immediate correspondence between the request and the response containing essential information to analyse the problem It's application problem and the application have to handle it. Log all the request/responses on the server or the client side.

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-06 Thread Rossen Raykov
* the immediate correspondence between the request and the response containing essential information to analyse the problem It's application problem and the application have to handle it. Log all the request/responses on the server or the client side. * newbies They have

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-06 Thread Lennart Regebro
From: Rossen Raykov [EMAIL PROTECTED] Shall the dump help the regular surfer? I doubt so. Shall it benefit the developer or the tester? Most probably not since they are not performing their activities on the production site. Oh, they most definitely help the developer or tester, because

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-06 Thread Rossen Raykov
Shall the dump help the regular surfer? I doubt so. Shall it benefit the developer or the tester? Most probably not since they are not performing their activities on the production site. Oh, they most definitely help the developer or tester, because errors do appear on production sites

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-06 Thread R. David Murray
On Sat, 6 Apr 2002, Rossen Raykov wrote: BUT: The developer has access to the system, and the dump doesn't have to be included in the HTML output. Maybe error dumps could be sent to a disk-log of some sort? Exactly that's my point. Log it with as many details as you can! From what he

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-05 Thread Dieter Maurer
Rossen Raykov writes: ... 1. the server log 2. the output to the client. ... In the second case it is better if Zope is returning just the error or the response. In the XML-RPC case the error have to be a valid XML-RPC response, not a stack trace. Thus, this may mean an exception

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-04 Thread Shane Hathaway
Rossen Raykov wrote: My point was that Zope is revealing internal information that is believed to be private and invisible for the Internet users. It happens in its default (debug) installation and even after -D option is removed from the startup script. Rossen and others interested in

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-04 Thread Dieter Maurer
Shane Hathaway writes: If you can, please check out the latest Zope from CVS. Tracebacks no longer appear by default, and even when they do, they do not show any filesystem paths. (If you already have a checkout, make sure you use cvs up -dP to get the new product.) I am very

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-04 Thread Rossen Raykov
, April 04, 2002 2:55 PM Subject: Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling. Shane Hathaway writes: If you can, please check out the latest Zope from CVS. Tracebacks no longer appear by default, and even when they do, they do not show any filesystem paths. (If you already have

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-03 Thread R. David Murray
On Tue, 2 Apr 2002, Eron Lloyd wrote: The problem here seems to be that you are trying to do XML-RPC communication with a version of Zope that doesn't support XML-RPC out of the box. You I think most people missed the point here. I don't think Rossen is asking for help on running zope or

RE: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-03 Thread Brian Lloyd
I think most people missed the point here. I don't think Rossen is asking for help on running zope or getting xml-rpc to work with it. He's observed a security problem: he believes the fact that a traceback including path names is included in the error response is a security exposure.

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-03 Thread Rossen Raykov
] isecure XML-RPC handling. I think most people missed the point here. I don't think Rossen is asking for help on running zope or getting xml-rpc to work with it. He's observed a security problem: he believes the fact that a traceback including path names is included in the error response

Re: [Zope-dev] Re: [Zope] isecure XML-RPC handling.

2002-04-02 Thread Martijn Pieters
On Tue, Apr 02, 2002 at 04:01:41PM -0500, Eron Lloyd wrote: On that thought, I'd like to see Zope.org become much more modern, and reflect the *latest* and *greatest* functionality of Zope. Deprecation of the hybrid PTK that's used, as well as updating and polishing of the site regularly.