[Zope-dev] vulnerability in stock Zope

seb bacon seb@jamkit.com
Thu, 11 Jul 2002 15:09:19 +0100


Production sites running a stock Zope are vulnerable to abuse of their 
server if they have not removed the 'Examples' folder.  For example, 
anyone could use http://notcarefulenough.com/Examples/FileLibrary as a 
warez repository.

I propose changing the 'View' permission on the entire folder to 
'Manager'-only to protect some of us from ourselves ;-)

Any objections?

seb