Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 30 Oct 2002 17:58:15 +0900
From:      Tetsurou Okazaki <okazaki@FreeBSD.org>
To:        Kris Kennaway <kris@obsecurity.org>
Cc:        developers@FreeBSD.org, www@FreeBSD.org
Subject:   Re: Web send-pr interface disabled
Message-ID:  <87fzuogv6h.wl@isola-uywb1ssu0.isolanet>
In-Reply-To: <20021029184819.GA94062@xor.obsecurity.org>
References:  <20021029184819.GA94062@xor.obsecurity.org>

next in thread | previous in thread | raw e-mail | index | archive | help
At Tue, 29 Oct 2002 10:48:19 -0800,
Kris Kennaway wrote:
> 
> I did a chmod 0 on the send-pr.html file on www.freebsd.org to stop
> the latest attention tantrum from our pet troll (see ports@).
> 

Drop permission bits of the front-end html file which contain the form
is not enough for a workaround, since trolls can post abused requests
via another web servers using a copy of the send-pr.html.

It is required to turn off permissions of the dosendpr.cgi.

Tetsurou



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-www" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?87fzuogv6h.wl>