Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread Remy Maucherat
William A. Rowe, Jr. wrote: Mladen Turk wrote: Remy Maucherat wrote: Tomcat permits both '\' and '%5C' as path delimiters. When Tomcat is used behind a proxy (including, but not limited to, Apache HTTP server with mod_proxy and mod_jk) configured to only proxy some contexts, a HTTP request cont

Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread William A. Rowe, Jr.
Mladen Turk wrote: > Remy Maucherat wrote: >> >> Tomcat permits both '\' and '%5C' as path delimiters. When Tomcat is >> used behind a proxy (including, but not limited to, Apache HTTP server >> with mod_proxy and mod_jk) configured to only proxy some contexts, a >> HTTP request containing strings

Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread Remy Maucherat
Mladen Turk wrote: Remy Maucherat wrote: Tomcat permits both '\' and '%5C' as path delimiters. When Tomcat is used behind a proxy (including, but not limited to, Apache HTTP server with mod_proxy and mod_jk) configured to only proxy some contexts, a HTTP request containing strings like "/\..

Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread Mladen Turk
Remy Maucherat wrote: Tomcat permits both '\' and '%5C' as path delimiters. When Tomcat is used behind a proxy (including, but not limited to, Apache HTTP server with mod_proxy and mod_jk) configured to only proxy some contexts, a HTTP request containing strings like "/\../" may allow attacke

Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread Peter Rossbach
+1, Jep, this explain better the real problem :-) Peter Am 20.03.2007 um 15:10 schrieb Remy Maucherat: Remy Maucherat wrote: -1 for the report summary posted at: http://tomcat.apache.org/security-4.html http://tomcat.apache.org/security-5.html http://tomcat.apache.org/security-6.html It is

Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread Yoav Shapira
Hi, On 3/20/07, Remy Maucherat <[EMAIL PROTECTED]> wrote: Due to the impossibility to guarantee that all URLs are handled by Tomcat as they are in proxy servers, Tomcat should always be secured as if no proxy restricting context access was used. Comments ? +1 to your reworked text, I like it.

Re: [Fwd: Vendor Notification VU#239041 - apache-tomcat]

2007-03-20 Thread Remy Maucherat
Remy Maucherat wrote: -1 for the report summary posted at: http://tomcat.apache.org/security-4.html http://tomcat.apache.org/security-5.html http://tomcat.apache.org/security-6.html It is highly misleading. (moving to dev list since it's obviously not confidential) In particular, the beginnin