|
[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message] Re: XInclude: security risk 1
Simon St.Laurent wrote, > It reminds me a bit of the issues that David Megginson raised back at > XTech 2000: > http://www.xml.com/pub/a/2000/02/xtech/megginson.html > > I can't find David's original slides, You mean these? http://www.megginson.com/ugly/slides/slide0001.html There's also this thread of DMs on traffic analysis, http://lists.xml.org/archives/xml-dev/200101/msg00057.html which is related. And a little while ago I suggested this, http://lists.xml.org/archives/xml-dev/200206/msg00247.html which does similar firewall penetration tricks as ERHs example, only without XInclude, just a parser which retrieves external entities. Cheers, Miles
|
PURCHASE STYLUS STUDIO ONLINE TODAY!Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced! Download The World's Best XML IDE!Accelerate XML development with our award-winning XML IDE - Download a free trial today! Subscribe in XML format
|
|||||||||

Cart








