Saturday 20 December 2003 2:31:47 pm
I sent these bugs to a couple of the eZ-crew yesterday included screenshots when I noticed these problems (I sent an email with information about these bugs and how there must be problem with the eZ-role permissions on their site, which allowed posting/editing of classes around in the structure, allowing anyone to change url-forwarding/translations, removing language settings etc etc. at www.ez.no and all other eZ publish sites. Conclusion: eZ Systems have set up the roles (at www.ez.no) with wrong privileges, but there are also some bugs here.
Marco (answer to your accusations of the testing) : I have not changed information, not removed any information, or not messed up anything (but I could if I wanted to, but that is not my goal)..only given proof of these security issues (could not remove these objects, therefore I sent this mail to eZ, explaining these things, with ID so they could remove'em). (Achtung! I posted a comment, and it unfortunately ended up at the front page...not my fault!), therefore I startet to check some other things in this system, and found a lot of security problems. If I did not try to post anything, we wouldn't have found these bugs either..so please think a little about that Marco ;) Our company have used eZ publish for a long time, and I have given information to eZ Systems about a lot of bugs without doing any harm to the system, just testing it (it's important to do much more testing on this system, not just private on our own site. Every site has it's own weak points. I will continue testing on our own site, but also eZ publish general sites, to ensure better security for all eZ users, and give feedback on these problems. There are a couple of very serious bugs in this system (just give me a url, and I will tak down you site with just a browser). Have sent this information to eZ Systems a long time ago, but no solution is yet found. Didn't want to post these things here in the forum, because I do not want to have people hacking around at the eZ sites the world over, or take down alle eZ sites.. I therefore held back information to avoid this. I rather prefer to communicate private with eZ about a couple of security issues, and hope to get solutions so everyone can get a more secure eZ publish installation. But an important issue is that everyone setting up roles in the eZ publish system, must know what they are doing, and test their roles, so we avoid these things.
Best regards Zinistry
And take a look at:
This was the first topic about these issues: http://www.ez.no/developer/ez_publish_3/forum/developer/lol_strange#msg40867
|