Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!]

This WebDNA talk-list message is from

2011


It keeps the original formatting.
numero = 107124
interpreted = N
texte = --Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii > Does anybody know how to stop this = (http://www.webdna.us/page.dna?numero=3D195&if=3D) from happening? It = looks like any DNA tag can easily be replaced through the URL. This = could potentially create security issues for us. umm.. yeah. that was what we were talking about in several posts in = this thread all morning, right? Did you try the code I posted? ..or the code Donovan posted? Set up a test page with an [if]...[/if] in it.. and then see if you can = break it with an URL param such as above.. and then see if you can patch = the security hole with code like one of us posted. Donovan, I am going to test something(s) and properly reply to you.. a = little later. -Govinda --Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii

Does  anybody = know how to stop this (http://www.w= ebdna.us/page.dna?numero=3D195&if=3D) from happening? It looks = like any DNA tag can easily be replaced through the URL. This could = potentially create security issues for = us.

umm.. yeah.  that was what we were = talking about in several posts in this thread all morning, = right?
Did you try the code I posted?  ..or the code Donovan = posted?
Set up a test page with an [if]...[/if] in it.. and = then see if you can break it with an URL param such as above.. and then = see if you can patch the security hole with code like one of us = posted.

Donovan, I am going to test = something(s) and properly reply to you.. a little = later.

-Govinda


= --Apple-Mail-3-704544720-- Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  2. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  3. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  4. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  5. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  6. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  7. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  8. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  9. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  10. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  11. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  12. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
--Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii > Does anybody know how to stop this = (http://www.webdna.us/page.dna?numero=3D195&if=3D) from happening? It = looks like any DNA tag can easily be replaced through the URL. This = could potentially create security issues for us. umm.. yeah. that was what we were talking about in several posts in = this thread all morning, right? Did you try the code I posted? ..or the code Donovan posted? Set up a test page with an [if]...[/if] in it.. and then see if you can = break it with an URL param such as above.. and then see if you can patch = the security hole with code like one of us posted. Donovan, I am going to test something(s) and properly reply to you.. a = little later. -Govinda --Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii

Does  anybody = know how to stop this (http://www.w= ebdna.us/page.dna?numero=3D195&if=3D) from happening? It looks = like any DNA tag can easily be replaced through the URL. This could = potentially create security issues for = us.

umm.. yeah.  that was what we were = talking about in several posts in this thread all morning, = right?
Did you try the code I posted?  ..or the code Donovan = posted?
Set up a test page with an [if]...[/if] in it.. and = then see if you can break it with an URL param such as above.. and then = see if you can patch the security hole with code like one of us = posted.

Donovan, I am going to test = something(s) and properly reply to you.. a little = later.

-Govinda


= --Apple-Mail-3-704544720-- Govinda

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

all records returned. (1997) order in the search? (2003) How far do [showif]s go? (1997) Associative lookup style? (1997) New WebCatalog Version !!! (1997) 5.0 Pricing (2003) Remove WebDNA context (2001) [OT] Communigate List (2003) [WebDNA] sum in a search (2009) Sendmail Recipients (2001) Questions about maximum (1999) Sorting Numbers (1997) installing webcatalog problem. HELP! (1998) [OT] Games (2005) crash again (1998) Help! Odd, irreproducible happenings. (1998) No shipping systems available? (1998) Formvariables + Netscape + Frame Set = Confusion (2000) So many lookers, hey smith micro (2003) [SubTotal] ??? (1998)