XMLRPC plugin, documentation patch
Martijn van de Streek <[email protected]>
| Newsgroups | gmane.comp.web.pyblosxom.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, I was _almost_ bitten by this: if a) Your config.py is world-readable, and your webserver happily servers .py files, and you use mod_rewrite tricks to put the pyblosxom.cgi and config.py outside 'base_url', or b) You're on a shared webserver it might be possible for attackers to read your XMLRPC passwords directly from your config file. I've added 2 lines of extra warnings about this to the xmlrpc 'setup howto' at the top of xmlrpc.py. Martijn -- Sorry isn't an excuse when you do something stupid on purpose. ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ Pyblosxom-devel mailing list Pyblosxom-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/pyblosxom-devel
signature.asc
(application/pgp-signature, 191 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFFAAkWDafvoz+l4DERAnySAJ9+Y8tCh34XTRzosziF+e7CN+2kPQCfayWe VygjS8CTVVGfbyWPOPKyj28= =fA5P -----END PGP SIGNATURE-----