r1 - 04 Jun 2007 - 07:47:49 - ChristianFoliniYou are here: TWiki >  Main Web > Task55Start

Task55Start - Protect Remo Demo Site

See TasksExplained? for more infos about tasks. This task is based on the template at TaskTemplateStart

Status : closed
Category : administrative
Date opened : 2007-xx-xx
Description : Protect the remo demo site from obvious attacks
Referenced in stories/tasks :
Testsuite : none
Commited revision : none

Remarks :

A whitehat was having fun with doing some xss attacks on the remo-demo site.


Changelog

2007-05-04 - Installed the mod-security-core-ruleset

This protects the remo demo site for the time being.

Remo has to get better input validation. Unfortunately, it is quite difficult to do it properly, as we have to accept regex input on certain fields. Basically anything could be valid for remo. Also things that look like a xss or sql injection...

TaskStati
TaskStatus? closed
Task-Categories administrative
Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
Main.TaskTemplateStart moved from Main.TaskTemplate on 19 Jan 2007 - 12:41 by ChristianFolini
 

No permission to view WebTopBar?

No permission to view WebBottomBar?