Re: hmmm
This WebDNA talk-list message is from 2006
It keeps the original formatting.
numero = 67406
interpreted = N
texte = Does the mod_rewrite fix take care of the issue that John describes below?Thanks,-Dan"I've confirmed through testing with the "Examples" page that any paired context ([context]something[/context]) can be broken by passing a null value as a URL value. If you use exclusively POST and not GET pages, you may be immune from this behavior (but it depends on your web server, since some will happily pass along URL parameters even to a POST)."-- John PeacockOn Wed, 07 Jun 2006 09:21:59 -0500 Clint Davis
wrote:> I went with Jesse's Apache mod_rewrite fix. Prevents trouble with any/all> virtual hosts.> > > On 6/6/06 11:58 PM, "Dan Strong" wrote:> >> Any word from SMSI on a fix for this?>> -Dan>> >> On Sat, 03 Jun 2006 20:55:21 -0700>> "Dan Strong" wrote:>>> Yowza.>>> -Dan>>> >>> On Tue, 30 May 2006 12:18:11 -0700>>> Jesse Proudman wrote:>>>> [This was reported to SM a week or two ago]>>>> >>>> On a security note...>>>> >>>> http://www.smithmicro.com/?text=&!=&math=>>>> >>>> I solved this on my servers using Mod Rewrite, but every one may want to do>>>> something to block>>>> it on their boxes. Make sure you don't store sensitive information>>>> (Authorize.net username />>>> passwords, etc) in text vars until you've got it patched.>>>> >>>> >>>> On May 30, 2006, at 11:38 AM, WJ Starck wrote:>>>> >>>>> Indeed.>>>>> >>>>> What else can ya say, in a day and age where security and>>>>> extensibility are at the forefront of many an admin's mind?>>>>> >>>>> R.I.P. beloved WebDNA...> > > > > -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to > Web Archive of this list is at: http://webdna.smithmicro.com/-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
Does the mod_rewrite fix take care of the issue that John describes below?Thanks,-Dan"I've confirmed through testing with the "Examples" page that any paired context ([context]something[/context]) can be broken by passing a null value as a URL value. If you use exclusively POST and not GET pages, you may be immune from this behavior (but it depends on your web server, since some will happily pass along URL parameters even to a POST)."-- John PeacockOn Wed, 07 Jun 2006 09:21:59 -0500 Clint Davis wrote:> I went with Jesse's Apache mod_rewrite fix. Prevents trouble with any/all> virtual hosts.> > > On 6/6/06 11:58 PM, "Dan Strong" wrote:> >> Any word from SMSI on a fix for this?>> -Dan>> >> On Sat, 03 Jun 2006 20:55:21 -0700>> "Dan Strong" wrote:>>> Yowza.>>> -Dan>>> >>> On Tue, 30 May 2006 12:18:11 -0700>>> Jesse Proudman wrote:>>>> [This was reported to SM a week or two ago]>>>> >>>> On a security note...>>>> >>>> http://www.smithmicro.com/?text=&!=&math=>>>> >>>> I solved this on my servers using Mod Rewrite, but every one may want to do>>>> something to block>>>> it on their boxes. Make sure you don't store sensitive information>>>> (Authorize.net username />>>> passwords, etc) in text vars until you've got it patched.>>>> >>>> >>>> On May 30, 2006, at 11:38 AM, WJ Starck wrote:>>>> >>>>> Indeed.>>>>> >>>>> What else can ya say, in a day and age where security and>>>>> extensibility are at the forefront of many an admin's mind?>>>>> >>>>> R.I.P. beloved WebDNA...> > > > > -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to > Web Archive of this list is at: http://webdna.smithmicro.com/-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
"Dan Strong"
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Running a store on BOTH http and https (1998)
View Source from cache (1997)
loops (2000)
# fields limited? (1997)
WebCat2b13MacPlugIn - syntax to convert date (1997)
Sitebuilder and databases not loading correctly (2005)
Webcat vs Tango (2000)
Signal Raised error (1997)
showif with math? (2000)
variables in [addlineitem] (1998)
PCS Frames (1997)
[WebDNA] Decode Base64 Image (2019)
Emailer and encryption (1997)
WebCat & cookies (1998)
ShowNext (1997)
Appending data from an IFrame (2002)
[WebDNA] [OT] the "Work in progress" thread. (2009)
[Fwd: Rotating Banners ... (was LinkExchange)] (1997)
[LOOKUP] (1997)
Size limit for tmpl editor ? (1997)