Re: Major Security Hole
This WebDNA talk-list message is from 1998
It keeps the original formatting.
numero = 18832
interpreted = N
texte = >I run a mac - webstar 2.1 and netcloak>I do NOT allow all webcatalog commands!>Yes, Oh crap! Us, too! Except there was no garbage of any kind to>interpret, just straight user, pass, groups data in easily readable text>with either of these URLs above modified with our domain name.>>We are on WebSTAR 2.1 and WebCat 2.0.1 (no NetCloak but we run DynaMorph,>Rumpus Pro, SiteEdit Pro, FlexMail and HomeDoor) and we do not allow all>WebCatalog commands either (just the default).>>WebCatalog is off line until this is resolved.According to the recent mails, the problem has something to do withNetCloak or similar tools.If it is not possible to parse the URL for :: and DATA with any of thementioned tools, I can install NetCloak on my machine and - if I am able toreproduce the problem - try to write a short, compiled 4D application(acgi) which you set up as a preprocessor (assuming you haven't one yet).Needs about 3 MB RAM and redirects to an error page (put nasty stuff onit...) Much of memory, yes, but you won't see a remarkable delay in speed.If the characters in question are not in the URL it simply does nothing. Nolicence fee.Of course, I have to check it first and it sounds somehow overdone - butcould help until the problem gets fixed otherwise. Send me a short privatereply if you want me to try it (po@ostry.com)Or ask Andreas Pardeike if you can set up his Welcome Plugin to check thespecial URL. Could work if you run WebStar and no additional multi-domainsoftware.http://welcome.comcon.deemail: pardeike@comcon.dePeter__________________________________________Peter Ostry - po@ostry.com - www.ostry.comOstry & Partner - Ostry Internet SolutionsAuhofstrasse 29 A-1130 Vienna Austriafon ++43-1-8777454 fax ++43-1-8777454-21
Associated Messages, from the most recent to the oldest:
>I run a mac - webstar 2.1 and netcloak>I do NOT allow all webcatalog commands!>Yes, Oh crap! Us, too! Except there was no garbage of any kind to>interpret, just straight user, pass, groups data in easily readable text>with either of these URLs above modified with our domain name.>>We are on WebSTAR 2.1 and WebCat 2.0.1 (no NetCloak but we run DynaMorph,>Rumpus Pro, SiteEdit Pro, FlexMail and HomeDoor) and we do not allow all>WebCatalog commands either (just the default).>>WebCatalog is off line until this is resolved.According to the recent mails, the problem has something to do withNetCloak or similar tools.If it is not possible to parse the URL for :: and DATA with any of thementioned tools, I can install NetCloak on my machine and - if I am able toreproduce the problem - try to write a short, compiled 4D application(acgi) which you set up as a preprocessor (assuming you haven't one yet).Needs about 3 MB RAM and redirects to an error page (put nasty stuff onit...) Much of memory, yes, but you won't see a remarkable delay in speed.If the characters in question are not in the URL it simply does nothing. Nolicence fee.Of course, I have to check it first and it sounds somehow overdone - butcould help until the problem gets fixed otherwise. Send me a short privatereply if you want me to try it (po@ostry.com)Or ask Andreas Pardeike if you can set up his Welcome Plugin to check thespecial URL. Could work if you run WebStar and no additional multi-domainsoftware.http://welcome.comcon.deemail: pardeike@comcon.dePeter__________________________________________Peter Ostry - po@ostry.com - www.ostry.comOstry & Partner - Ostry Internet SolutionsAuhofstrasse 29 A-1130 Vienna Austriafon ++43-1-8777454 fax ++43-1-8777454-21
Peter Ostry
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Not really WebCat (1997)
WebCat2b15MacPlugin - showing [math] (1997)
multiple search commands (1997)
Almost a there but..bye bye NetCloak (1997)
Erotic Sites (1997)
Re:my First Ship table (1998)
Problems with [Search] param - Mac Plugin b15 (1997)
Separate SSL Server (1997)
Writefile doesn't work, which permissions to use? (2005)
Execute Applescript (1997)
File Uploads... (1997)
WebCatalog 2.0 b 15 mac (1997)
quantity minimum problem (1997)
Running _every_ page through WebCat-error.html (1997)
E-Mail Preferences in Admin Folder (1997)
WebDNA 4.5.1 Now Available (2003)
Function basic question (2006)
Separate SSL Server (1997)
math problems (2000)
Mondo amounts of Mail [long] (1999)