[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: SOAP, plague, love

  • From: Matt Sergeant <matt@s...>
  • To: Dave Winer <dave@u...>
  • Date: Sat, 6 May 2000 11:04:01 +0100 (BST)

xss progress software
On Fri, 5 May 2000, Dave Winer wrote:

> Not running an HTTP server? Then you'll never get one.

So, all new Red Hat linux installations will though. (I know that's Red
Hat's fault - but the ILOVEYOU virus is MS's fault - but blame doesn't
stop it spreading).

> Can a firewall administrator block SOAP and XML-RPC messages? Absolutely.

Not easily with Linux ipchains firewalls. We're talking 30% of the world's 
web servers here.

As for XML-RPC being only as inherently insecure as CGI's, well that may
be true. But we're still discovering wierd security issues with CGI's that
even careful CGI writers have been bitten by (XSS). I await with interest
the XML-RPC/SOAP cert advisories ;-) While I do mean that humorously (I
hope it never happens) let's not be naive here. XML-RPC is something
new. So was Javascript, and it was also designed to be secure from the
outset. So was Java. All had (have) security bugs.

-- 
<Matt/>

Fastnet Software Ltd. High Performance Web Specialists
Providing mod_perl, XML, Sybase and Oracle solutions
Email for training and consultancy availability.
http://sergeant.org http://xml.sergeant.org



***************************************************************************
This is xml-dev, the mailing list for XML developers.
To unsubscribe, mailto:majordomo@x...&BODY=unsubscribe%20xml-dev
List archives are available at http://xml.org/archives/xml-dev/
***************************************************************************

PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.