XMLRPC plugin, documentation patch

Martijn van de Streek <[email protected]>
Newsgroups gmane.comp.web.pyblosxom.devel
Message-ID <[email protected]>
Hello,

I was _almost_ bitten by this: if
a) Your config.py is world-readable, and your webserver happily servers
   .py files, and you use mod_rewrite tricks to put the pyblosxom.cgi and
   config.py outside 'base_url', or 
b) You're on a shared webserver

it might be possible for attackers to read your XMLRPC passwords
directly from your config file.

I've added 2 lines of extra warnings about this to the xmlrpc 'setup
howto' at the top of xmlrpc.py.

Martijn
-- 
Sorry isn't an excuse when you do something stupid on purpose.

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642

_______________________________________________
Pyblosxom-devel mailing list
Pyblosxom-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/pyblosxom-devel
signature.asc (application/pgp-signature, 191 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFFAAkWDafvoz+l4DERAnySAJ9+Y8tCh34XTRzosziF+e7CN+2kPQCfayWe
VygjS8CTVVGfbyWPOPKyj28=
=fA5P
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.