Demo Discussion
Forum Config Examples Contributions Vulnerabilities
  Discussion forum about ELOG, Page 632 of 808  Not logged in ELOG logo
New entries since:Thu Jan 1 01:00:00 1970
ID Date Icon Author Author Email Categorydown OS ELOG Version Subject
  1604   Wed Jan 18 12:57:30 2006 Reply Stefan Rittstefan.ritt@psi.chBug report  Re: In version 2.6 the themes do not work right on Windows.

Quote:
The URL is fixed at whichever logbook that is selected (e.g. ELOG 2.5.9-4 is <link rel="stylesheet" type="text/css" href="default.css"> & ELOG 2.6.0-1 is <link rel="stylesheet" type="text/css" href="http://localhost:8080/demo/default.css">).


So what is your problem? Can't you access http://localhost:8080/demo/default.css ?

If so, you could use an
URL = http://{your host}:8080/

option in your config file, where you replace {your host} with your real host name.
  1605   Wed Jan 18 13:06:50 2006 Reply Stefan Rittstefan.ritt@psi.chBug report 2.6.0Re: Attribute substitution in email configuration

Adam Blandford wrote:
Not sure if this functionality is intended or is a bug.


It was not implemented, however you call this Wink

I added that in the current SVN version, so it will be contained in the next release.
  1607   Wed Jan 18 17:20:45 2006 Warning Chris Warnerchristopher_warner@dcd.uscourts.govBug reportLinux2.6Buffer Overflow?
Users can access root level directories by using a modified URL. I saw on some security web sites that this was a problem in previous versions. Was it not fixed in 2.6?

To recreate enter http://yourhost.yourdomain.com/../../../../etc/passwd

view your password file in the browser.


If this was previously reported, is there a fix?

Chris Warner
  1608   Thu Jan 19 10:31:05 2006 Reply Stefan Rittstefan.ritt@psi.chBug reportLinux2.6Re: Buffer Overflow?

Chris Warner wrote:
Users can access root level directories by using a modified URL. I saw on some security web sites that this was a problem in previous versions. Was it not fixed in 2.6?

To recreate enter http://yourhost.yourdomain.com/../../../../etc/passwd

view your password file in the browser.

If this was previously reported, is there a fix?

Chris Warner


Thanks for telling me, I didn't know. I was able to reproduce your problem under certain conditions, and I just released version 2.6.1 to fix it. However it has nothing to do with an old buffer overflow (see elog:941).

I would strongly advise everybody to upgrade as soon as possible.
  1609   Thu Jan 19 15:02:38 2006 Question Giorgio Croci Candianig.crocic@libero.itBug report 2.6.1Access to global configuration in v2.6.1
Hi,
I just installed v.2.6.1 coming from the previous 2.6.0 (on Win2000)
When I access the "configuration" function from a logbook, in the cfg page I only see two buttons in the header
(save or cancel); in the previous version I saw more buttons there ("global config", "create new logbook" and so
on), so here I'm unable to access global configuration or logbook management (except for current logbook options).
I am logged in as admin (actually I have a single-user configuration, thus no particular users defined).
I hope this report may be helpful, and not just being caused by a misunderstanding on my side ;)
Thanks
GiorgioCC
  1610   Thu Jan 19 15:23:02 2006 Reply Stefan Rittstefan.ritt@psi.chBug report 2.6.1Re: Access to global configuration in v2.6.1
> I just installed v.2.6.1 coming from the previous 2.6.0 (on Win2000)
> When I access the "configuration" function from a logbook, in the cfg page I only see two buttons in the header
> (save or cancel); in the previous version I saw more buttons there ("global config", "create new logbook" and so
> on), so here I'm unable to access global configuration or logbook management (except for current logbook options).

I tried to reproduce your problem, but could not. In my windows installation it looks fine. You only see the
(save and cancel) buttons only if you go to "Change [global]", otherwise you see the "Change [global]", "Delete
this logbook" etc. buttons. Have you tried with the default elogd.cfg which comes from the distribution?
  1613   Thu Jan 19 20:50:29 2006 Cool Mark Coudrietmarkcoudriet@yahoo.comBug report 2.6.0Re: In version 2.6 the themes do not work right on Windows.

Stefan Ritt wrote:

Quote:
The URL is fixed at whichever logbook that is selected (e.g. ELOG 2.5.9-4 is <link rel="stylesheet" type="text/css" href="default.css"> & ELOG 2.6.0-1 is <link rel="stylesheet" type="text/css" href="http://localhost:8080/demo/default.css">).


So what is your problem? Can't you access http://localhost:8080/demo/default.css ?

If so, you could use an
URL = http://{your host}:8080/

option in your config file, where you replace {your host} with your real host name.


No, because they would have to be in every logbook instead of coming out of the theme directory.
But I just updated to your new version 2.6.1 & everything is fine now. Thanks for your help! Big grin
  1614   Thu Jan 19 20:53:01 2006 Reply Stefan Rittstefan.ritt@psi.chBug report 2.6.0Re: In version 2.6 the themes do not work right on Windows.

Mark Coudriet wrote:
But I just updated to your new version 2.6.1 & everything is fine now. Thanks for your help! Big grin


Japp. I switched back to relative links for CSS again, seems to give less trouble. Pleased
ELOG V3.1.5-3fb85fa6