Branches
Comments
[»]
Frequently updated
by Payton - Aug 10th 2004 11:37:24
There are often new updates available that aren't always posted here.
Please check out the home page for more information.
[reply]
[top]
[»]
Major security hole: can browse outside topdir!
by Ferenc Veres - Mar 5th 2004 06:02:10
Hi!
Excellent project, congratulations!
I have my music shared from my ~lion/music, and ppl havnig access in the
room to control the music, can browse folders above the configured
"topfolder", e.g. they can click on /home/lion and browse my
folders!!!
Please make sure, that no way anyone can go out of top, not even by
altering the URL. (What I usually do, is sending/receiving only the part
which is BELOW the topdir fo an application, and always add the topdir when
referring to local dirs and files in the code. Make sure you deny accessing
"subdirs" containing ".." too.
Keep up the good work, and many thanks!
[reply]
[top]
|