RE: [Zope] is WebDAV a security hole?

2000-06-05 Thread Brian Lloyd
Been playing around with WebDAV from IE5 connecting to a RedHat 6.1 +Zope 2.1.6 And it seems that quite a bit of the stuff that propably shouldn't be visible can be seen, for example acl_users What other things are you referring to? (see answer for acl_users below) Without being

Re: [Zope] is WebDAV a security hole?

2000-06-05 Thread Jacob Lundqvist
Brian Lloyd wrote: If I used some other WebDAV client, could I then download acl_users, and if so, would this expose usernames/passwords? It would not expose passwords - I believe that what you are seeing is a sort of non-obvious but basically harmless thing. User folders (acl_users)

RE: [Zope] is WebDAV a security hole?

2000-06-05 Thread Brian Lloyd
Thanx for an informative response! Btw I tried WebDAV vs. www.zope.org and that site refused the connection attempt. Is there some obvious setting that I can use to disable WebDAV, since I don't need it (as far as I know;) DAV won't work for zope.org because it runs behind apache and