Re: Major Security Hole
This WebDNA talk-list message is from 1998
It keeps the original formatting.
numero = 18828
interpreted = N
texte = >Oh crap! I get someting similar I can see all of my groups and user>names but the passwords appear as a string of weird characters. Now I>don't know if the characters can be interpreted or if it is just garbage.>I would prefer that nothing gets returned.>>I get the user group text string returned if I request:>>http://server.com/webcatalog/users.db::$data>>I also get the text string returned if I only request:>>http://server.com/webcatalog/users.db:>>I run a mac - webstar 2.1 and netcloak>I do NOT allow all webcatalog commands!Yes, Oh crap! Us, too! Except there was no garbage of any kind tointerpret, just straight user, pass, groups data in easily readable textwith either of these URLs above modified with our domain name.We are on WebSTAR 2.1 and WebCat 2.0.1 (no NetCloak but we run DynaMorph,Rumpus Pro, SiteEdit Pro, FlexMail and HomeDoor) and we do not allow allWebCatalog commands either (just the default).WebCatalog is off line until this is resolved.
Associated Messages, from the most recent to the oldest:
>Oh crap! I get someting similar I can see all of my groups and user>names but the passwords appear as a string of weird characters. Now I>don't know if the characters can be interpreted or if it is just garbage.>I would prefer that nothing gets returned.>>I get the user group text string returned if I request:>>http://server.com/webcatalog/users.db::$data>>I also get the text string returned if I only request:>>http://server.com/webcatalog/users.db:>>I run a mac - webstar 2.1 and netcloak>I do NOT allow all webcatalog commands!Yes, Oh crap! Us, too! Except there was no garbage of any kind tointerpret, just straight user, pass, groups data in easily readable textwith either of these URLs above modified with our domain name.We are on WebSTAR 2.1 and WebCat 2.0.1 (no NetCloak but we run DynaMorph,Rumpus Pro, SiteEdit Pro, FlexMail and HomeDoor) and we do not allow allWebCatalog commands either (just the default).WebCatalog is off line until this is resolved.
Jim Turney
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Redirect (1998)
[WebDNA] WebDNA 6.1 Info (2008)
WebCat2b15MacPlugin - [protect] (1997)
Resetting a Formvariable (2000)
emailer 150 (1997)
A multi-processor savvy WebCatalog? (1997)
WebCatalog2 Feature Feedback (1996)
Summing fields (1997)
credit card # checker ??? (2004)
Absolute path (2003)
Clickable maps and WebCatalog? (1996)
UNSUBSCRIBE ME (2004)
[taxrate] question (1997)
b12 cannot limit records returned and more. (1997)
Re2: frames & carts (1997)
Updating a database once per day - An example (1998)
WebCat cannot handle compatible search parameters? (1997)
SetMIMEHeader ATTN:John P. (2001)
creator code (1997)
errors 550, and 108 (1998)