[Zope] [davidbro@namshub.org: Re: [Zope] BIG security hole in www.zope.org]

davidbro@namshub.org davidbro@namshub.org
Thu, 16 Sep 1999 15:13:23 -0700


--EeQfGwPcQSOJBaQU
Content-Type: text/plain; charset=us-ascii

forgot to copy the list.
--EeQfGwPcQSOJBaQU
Content-Type: message/rfc822

Date: Thu, 16 Sep 1999 15:12:36 -0700
From: davidbro@namshub.org
To: Andy Dustman <adustman@comstar.net>
Subject: Re: [Zope] BIG security hole in www.zope.org
Message-ID: <19990916151235.A4875@namshub.org>
References: <Pine.LNX.4.10.9909161743420.31596-100000@kenny.comstar.net> <19990916145159.A4811@namshub.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Mailer: Mutt 0.95.6i
In-Reply-To: <19990916145159.A4811@namshub.org>; from davidbro@namshub.org on Thu, Sep 16, 1999 at 02:51:59PM -0700

As of right now, the message is gone.  Either the hole is plugged, or
the website has been repaired.

> > Not only does this work, it lets me make the change. Which is why it
> > presently says, "Hey, man, if you can read this, something is seriously
> > hosed." On the members list, and every member page with the default
> > index_html. Probably the security is set wrong up above (I hope).

--EeQfGwPcQSOJBaQU--