Re: [Zope-dev] Re: information disclosure vulnerability

2002-12-03 Thread Jamie Heilman
> http://YourServer/Control_Panel/Products/ExternalEditor > > gives Anoynmous the ZopeStartPage if ExternalEditor is installed and a > SiteError if not. I believe this particular item can be worked around to a degree. In the index_html in the root folder I simply put: index_html This helps hide

[Zope-dev] Re: information disclosure vulnerability

2002-12-03 Thread Maik Jablonski
Jerome Alet wrote: probably the HelpSys object shouldn't be available by default to non-authenticated users, because it gives too much information on the currently installed products. access any Zope site this way : http://your.zope.site/HelpSys and you'll learn what products a