Re: [Zope-dev] Virtual Host Monster Paranoia

2001-02-13 Thread Matt Hamilton
On Tue, 13 Feb 2001, Chris Withers wrote: Right, I really like the idea of these things but I am concerned about something that allows anonymous users to futz with traversal. Can someone put my fears to rest that using these won't let anonymous users do bad things to my sites? I use

Re: [Zope-dev] Virtual Host Monster Paranoia

2001-02-13 Thread Toby Dickenson
On Tue, 13 Feb 2001 10:24:54 +, Chris Withers [EMAIL PROTECTED] wrote: I really like the idea of these things but I am concerned about something that allows anonymous users to futz with traversal. Can someone put my fears to rest that using these won't let anonymous users do bad things to

Re: [Zope-dev] Virtual Host Monster Paranoia

2001-02-13 Thread Toby Dickenson
On Tue, 13 Feb 2001 10:30:26 + (GMT), Matt Hamilton [EMAIL PROTECTED] wrote: I use them in conjunction with Apache's mod_proxy to rewrite http://www.simpledomain.com to the long http://zopehost.foo.com/blah/blah/VirtualHostMonstser/blah/blah. The Zope host is behind a firewall, so

RE: [Zope-dev] Virtual Host Monster Paranoia

2001-02-13 Thread Toby Dickenson
Then again, there's the advantage of having something included as a standard part of Zope. Yes, thats true. I would like to see this being rolled into the standard zope (and there is a Collector entry saying that), although I think its unlikely given the 'competition' from VHM. Having said

Re: [Zope-dev] Virtual Host Monster Paranoia

2001-02-13 Thread Evan Simpson
From: "Chris Withers" [EMAIL PROTECTED] Well, it's easy enough to find out if a site is running Zope, then this becomes pretty easy attack to think of I'm not going to claim that this is perfectly harmless, but I can't think of any way in which this could be termed an "attack". You can