To Zinistry Vacana: Hacking or what?

Author Message

Marco Zinn

Saturday 20 December 2003 1:31:14 pm

Hi Zinistry Vacana,

sorry, but i don't think, that you did something very usefull with this empty "top 10 ez tips" documentation object (
If you have some tips, create a documentation bit and WRITE THEM down. If you have nothing to write, don't create an enmpty document.

This, the comment to the XMAS vacation article and the other "hacking" of the reference list (now removed) does not seem as really you want to contribute to ezPublish. Sorry to be rude, but i visited yesterday and saw three useless/hacked contents and all were of you.
Are you new and this was just a mistake... or do you want to mess up?



Saturday 20 December 2003 2:31:47 pm

I sent these bugs to a couple of the eZ-crew yesterday included screenshots when I noticed these problems (I sent an email with information about these bugs and how there must be problem with the eZ-role permissions on their site, which allowed posting/editing of classes around in the structure, allowing anyone to change url-forwarding/translations, removing language settings etc etc. at and all other eZ publish sites. Conclusion: eZ Systems have set up the roles (at with wrong privileges, but there are also some bugs here.

Marco (answer to your accusations of the testing) :
I have not changed information, not removed any information, or not messed up anything (but I could if I wanted to, but that is not my goal)..only given proof of these security issues (could not remove these objects, therefore I sent this mail to eZ, explaining these things, with ID so they could remove'em).

(Achtung! I posted a comment, and it unfortunately ended up at the front page...not my fault!), therefore I startet to check some other things in this system, and found a lot of security problems. If I did not try to post anything, we wouldn't have found these bugs please think a little about that Marco ;)

Our company have used eZ publish for a long time, and I have given information to eZ Systems about a lot of bugs without doing any harm to the system, just testing it (it's important to do much more testing on this system, not just private on our own site. Every site has it's own weak points.

I will continue testing on our own site, but also eZ publish general sites, to ensure better security for all eZ users, and give feedback on these problems.

There are a couple of very serious bugs in this system (just give me a url, and I will tak down you site with just a browser). Have sent this information to eZ Systems a long time ago, but no solution is yet found.

Didn't want to post these things here in the forum, because I do not want to have people hacking around at the eZ sites the world over, or take down alle eZ sites.. I therefore held back information to avoid this.

I rather prefer to communicate private with eZ about a couple of security issues, and hope to get solutions so everyone can get a more secure eZ publish installation.

But an important issue is that everyone setting up roles in the eZ publish system, must know what they are doing, and test their roles, so we avoid these things.

Best regards

And take a look at:
This was the first topic about these issues:

Marco Zinn

Sunday 21 December 2003 1:32:28 am

Thanks for your clarifications.
I agree with your procedure (informing ez by mail, not here). I did the same after I saw your comments, shown at the wrong places, on
I didn't know, that you test ez for security, because i don't remember to see any posts of you here before, and i'm usually reading forums and bug-reports quite often.
Now, I hope, that ez will catch up with your hints an close the security bugs.
And it would be good, if someone could write some documentation about how to set roles/permissions right, as far is this is a configuration issue.

And what about the Top10 EZ Tips? Will you fill this with content? The header is quite attracting ;)



Sunday 21 December 2003 6:56:01 am

;) Tnx for your understanding Marco!

I also read forum-messages and bug reports..and the reason why you haven't seen me here, is that I use other alias-names/nicks, just to be more secure with everything...(but I'm also active here) ;)

Well..about the role permissions, I haven't found any doc. on this at In our company I have checked the roles, developed some, and also split up a couple of roles so they are more secure , but this also need some more testing. Maybe I get the time to write a short doc. on this topic..but need feedback from eZ if they are planning to change the permission system in the future..then I have to wait.

A lot of modules in the permission-system are added (from v.3.0 -> if I'm not wrong), and the most important ones today are:

Where's the documentation on on what every part of this means, and how to set up the permissions right for these modules?
That's the magical Christmas-question ;) ..but if you set up the permissions right, there are still bugs :(

I think eZ waits to document some stuff in the system because of possible future changing, and think also there exists a lot more doc. from eZ Systems on "howto" do stuff in eZ publish other than you can find on (but it's maybe beeing used as internal doc.), like all of us have our own doc.

How can we share this the best way, and how can we inform people to publish information/code which eZ has developed for them, to get a better community which reduce our development costs and we don't have to develope the same things twice, because we don't know that these modules we need already exist?

This have to be a question eZ Systems have to answer, how we can get hold of more already developed code, examples and information, to reduce our costs, and so we also can use more resources on testing extraordinary eZ publish developed stuff rather than to develope twice.

What about a page that describes what eZ Systems already have developed for their customers where we can download these things if the paying company agrees? The paying companies would also make profit on this idea.

"Our goal is to reduce costs in the development of this open source product", so we (the people) have to be more OSP's ;)
(O)pen (S)ource (P)articipant's
...and support this Open Source Product by doing some hardcore-testing to achieve better security ;)

***Wünsche euch alle eine Frohe Weihnachten und einen Guten Rutsch ins neue Jahr!***


Sunday 21 December 2003 12:08:14 pm

Marco, about the Top 10 eZ tip, of course this would be a cool idea..but I think the eZ publish crew have to decide the content here ;)

Paul Borgermans

Sunday 21 December 2003 2:38:41 pm

Well Zinistry,

You made Jan (amos) to work on sundays. In svn, part of what you are referring to is fixed now.


eZ Publish, eZ Find, Solr expert consulting and training


Monday 22 December 2003 12:42:11 am

I'm really sorry about that, but because of problems with eZ publish in my company, I have been working almost every weekend for the last year (and I'm really looking forward to a new year with less trouble with this system).

My opinion is that the eZ crew need to put more effort on testing, don't you agree?

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 19:33:35
Script start
Timing: Jan 18 2025 19:33:35
Module start 'layout'
Timing: Jan 18 2025 19:33:35
Module start 'content'
Timing: Jan 18 2025 19:33:36
Module end 'content'
Timing: Jan 18 2025 19:33:36
Script end

Main resources:

Total runtime1.3439 sec
Peak memory usage4,096.0000 KB
Database Queries71

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0085 587.9297152.6250
Module start 'layout' 0.00850.0033 740.554739.4609
Module start 'content' 0.01191.3304 780.0156650.9297
Module end 'content' 1.34230.0015 1,430.945320.1563
Script end 1.3438  1,451.1016 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00340.2549160.0002
Check MTime0.00140.1014160.0001
Mysql Total
Database connection0.00150.114710.0015
Looping result0.00070.0531690.0000
Template Total1.308697.420.6543
Template load0.00270.202220.0014
Template processing1.305997.175120.6529
Template load and register function0.00010.009110.0001
Cache load0.00240.1780780.0000
Sytem overhead
Fetch class attribute can translate value0.00090.064630.0003
Fetch class attribute name0.00200.148890.0002
Image XML parsing0.00120.088630.0004
Instantiating content class attribute0.00000.0012100.0000
String conversion0.00000.000640.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
3content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
7content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
15content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
9content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 36
 Number of unique templates used: 6

Time used to render debug report: 0.0002 secs