eZ publish 3.2 vulnerable to spam attacks

eZ publish 3.2 vulnerable to spam attacks

Friday 24 October 2003 8:13:55 am - 7 replies

Author Message

Paul Forsyth

Friday 24 October 2003 8:32:09 am

Im sure it will. Security is always a priority.

paul

Jan Borsodi

Monday 27 October 2003 7:05:34 am

I'm currently looking into this problem, the fix will be part of the 3.2-3 release.
Thanks for the notice.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Jan Borsodi

Tuesday 28 October 2003 2:11:25 am

The module will be turned off by default in 3.2-3 and 3.3 (uses a separate setting). The reason for this is that the module is insecure by design and should only be used if you really need this kind of functionality.

As for 3.3 I would recommend using the new revised information collector system, you will be able to do the same things you have in your fix.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Paul Forsyth

Tuesday 28 October 2003 2:24:11 am

Does this affect current 3.2-2 information collectors? We have several sites using this.

Paul

Jan Borsodi

Tuesday 28 October 2003 4:16:32 am

The 'spam attack' problem is not in the information collection system but in the separate form module.
This module will fetch all POST variables, generate a mail out of it and send it.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Paul Forsyth

Tuesday 28 October 2003 4:22:27 am

My post was referring to the switching off of the process module. You mentioned that users should use the new improved information collecter routines in ez3.3. If the form module is seperate why mention this?

This implied that the switching of the module affects current info collector routines. Does it?

paul

Jan Borsodi

Wednesday 29 October 2003 1:47:36 am

> This implied that the switching of the module affects current
> info collector routines. Does it?

No, the switch is only for the form/process module.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

You must be logged in to post messages in this topic!

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.