Search found 8 matches

by Teme
Sat Nov 01, 2008 12:02 pm
Forum: Modules/Add-Ons
Topic: ForumMadeSimple feature request
Replies: 9
Views: 2686

Re: ForumMadeSimple feature request

alby is righ. When the software gets html-tags from unknown sources, it has to have good "whitelist" and tag parser has to be 100% correct. Otherwise the system becomes vulnerable to cross site scripting bug. Much better practice is to translate non-html tags to html and ignore unknown tag...
by Teme
Fri Oct 31, 2008 9:56 pm
Forum: Layout and Design (CSS & HTML)
Topic: How To Set My Home Page?
Replies: 3
Views: 1590

Re: How To Set My Home Page?

Following configuration problems are existing in this installation: * Default page does not include index.php ** At Apache's https.conf I have: DirectoryIndex index.html index.htm index.shtml index.php * It does not deny the file listing under the directory c:/htdocs ** At Apache the Options -direct...
by Teme
Thu Oct 30, 2008 3:46 pm
Forum: [locked] Quality Assurance
Topic: The Quality Assurance Team
Replies: 15
Views: 33466

Re: The Quality Assurance Team

Good news. Now I have taken over the QATeam. I have began to formalize the work with small team which will be announced later. I have initial permission to use some of my co-workers from quality consulting company to formalize the testing efforts. It is project for us, so it will end at some point. ...
by Teme
Thu Oct 30, 2008 9:42 am
Forum: CMSMS Core
Topic: [solved] Has anyone had a 403 (Error 403: Forbidden) error caused
Replies: 5
Views: 2030

Re: Has anyone had a 403 (Error 403: Forbidden) error caused by the word "from" when

Another option is that there is some other web application firewall (WAF) between your browser and the server.  "from"-word is keyword at SQL so WAF might think that someone is trying SQL-injection.

Teme
by Teme
Thu Oct 30, 2008 8:25 am
Forum: [locked] Quality Assurance
Topic: The Quality Assurance Team
Replies: 15
Views: 33466

Re: The Quality Assurance Team

I sent request to join to QATeam yesterday. Hopefully the admins of that group will read their mail every now and then.

The plan is to start to formalize the testing efforts. But we'll see... Ted knows more about the plans.

Teme
by Teme
Mon Oct 27, 2008 8:22 pm
Forum: [locked] Quality Assurance
Topic: Possible security issue: Cross-site request forgery
Replies: 6
Views: 17053

Re: Possible security issue: Cross-site request forgery

Even with the local site there is real danger, if the local site has interactive components like discussion forums with img-tag. That is not exploiting the post-forms, but it still can cause plenty of problems.

Teme
by Teme
Mon Oct 27, 2008 9:21 am
Forum: [locked] Quality Assurance
Topic: The Quality Assurance Team
Replies: 15
Views: 33466

Re: The Quality Assurance Team

It looks like this group is not very active. I'd like to know who has the main responsibility of the QA activities at the moment.

Teme
by Teme
Sat Oct 25, 2008 5:20 pm
Forum: [locked] Quality Assurance
Topic: Possible security issue: Cross-site request forgery
Replies: 6
Views: 17053

Re: Possible security issue: Cross-site request forgery

Hi, I have discussed about this with develpers at IRC. I was most likely the one, who originally found the problem.Obfuscating is really bad way to secure the system, but at the moment only way to do it. The real fix is much more complex. All links which are able modify any data should be secured wi...

Go to advanced search