Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!]

This WebDNA talk-list message is from

2011


It keeps the original formatting.
numero = 107124
interpreted = N
texte = --Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii > Does anybody know how to stop this = (http://www.webdna.us/page.dna?numero=3D195&if=3D) from happening? It = looks like any DNA tag can easily be replaced through the URL. This = could potentially create security issues for us. umm.. yeah. that was what we were talking about in several posts in = this thread all morning, right? Did you try the code I posted? ..or the code Donovan posted? Set up a test page with an [if]...[/if] in it.. and then see if you can = break it with an URL param such as above.. and then see if you can patch = the security hole with code like one of us posted. Donovan, I am going to test something(s) and properly reply to you.. a = little later. -Govinda --Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii

Does  anybody = know how to stop this (http://www.w= ebdna.us/page.dna?numero=3D195&if=3D) from happening? It looks = like any DNA tag can easily be replaced through the URL. This could = potentially create security issues for = us.

umm.. yeah.  that was what we were = talking about in several posts in this thread all morning, = right?
Did you try the code I posted?  ..or the code Donovan = posted?
Set up a test page with an [if]...[/if] in it.. and = then see if you can break it with an URL param such as above.. and then = see if you can patch the security hole with code like one of us = posted.

Donovan, I am going to test = something(s) and properly reply to you.. a little = later.

-Govinda


= --Apple-Mail-3-704544720-- Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  2. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  3. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  4. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  5. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  6. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  7. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  8. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  9. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Govinda 2011)
  10. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  11. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
  12. Re: [WebDNA] Error: Can't open order file. Ignoring [OrderFile] context Error: Error: expected [/APPLICATION], but found [/!] instead[/!] (Kenneth Grome 2011)
--Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii > Does anybody know how to stop this = (http://www.webdna.us/page.dna?numero=3D195&if=3D) from happening? It = looks like any DNA tag can easily be replaced through the URL. This = could potentially create security issues for us. umm.. yeah. that was what we were talking about in several posts in = this thread all morning, right? Did you try the code I posted? ..or the code Donovan posted? Set up a test page with an [if]...[/if] in it.. and then see if you can = break it with an URL param such as above.. and then see if you can patch = the security hole with code like one of us posted. Donovan, I am going to test something(s) and properly reply to you.. a = little later. -Govinda --Apple-Mail-3-704544720 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii

Does  anybody = know how to stop this (http://www.w= ebdna.us/page.dna?numero=3D195&if=3D) from happening? It looks = like any DNA tag can easily be replaced through the URL. This could = potentially create security issues for = us.

umm.. yeah.  that was what we were = talking about in several posts in this thread all morning, = right?
Did you try the code I posted?  ..or the code Donovan = posted?
Set up a test page with an [if]...[/if] in it.. and = then see if you can break it with an URL param such as above.. and then = see if you can patch the security hole with code like one of us = posted.

Donovan, I am going to test = something(s) and properly reply to you.. a little = later.

-Govinda


= --Apple-Mail-3-704544720-- Govinda

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

[OT] Test - THE ANSWER _ The winner is .... (2003) Multiple FlushDatabases (2000) Problems with webcat 2.01 for NT (1997) Showing once on a founditems (1997) Running 2 two WebCatalog.acgi's (1996) creator code (1997) Quickie question on the email templates (1997) Q: old cart serial problem (2000) WebCat2: Master Counter snippet (1997) What am I missing (1997) WC1.6 to WC2 date formatting (1997) 1 cent answer? (1998) WebCatalog can't find database (1997) sort problems....bug or brain fart? (1997) Format of Required fields error message (1997) Ampersand (1997) redirect with frames (1997) ASP and Web DNA (1998) Protect vs Authenicate (1997) Dreamweaver noedit ??? (2005)