Subject: The mailing list for listmasters using Sympa
List archive
- From: Olivier Salaün <address@concealed>
- To: address@concealed
- Cc: address@concealed
- Subject: [sympa-users] Re: hide email addresses competly
- Date: Mon, 30 Jul 2007 16:18:18 +0200
Users should not be allowed to access arctxt/* or .mhonarc.db files through Sympa web interface ; that's a secutity weekness of current versions of Sympa.
We've fixed both code branches to disallow access to these files. Here is the patch : http://sourcesup.cru.fr/cgi/viewvc.cgi/branches/sympa-5.3-branch/wwsympa/wwsympa.fcgi?r1=4471&r2=4488&root=sympa&view=patch
address@concealed a écrit :
sorry if I repeat myself again, but I need to know how to protect the email
addresses from the website, which is public. I mean that even if I set the
site
to show the "AT" or to hide the email address, one can still retrieve all
those address simply looking inside:
http://www.mysite.com/sympa/mylist/2007-05/arctxt/1 or
http://www.mysite.com/sympa/mylist/.mhonarc.db
-
[sympa-users] hide email addresses competly,
alaxa, 07/24/2007
- [sympa-users] Re: hide email addresses competly, Olivier Salaün, 07/30/2007
Archive powered by MHonArc 2.6.19+.