Re: Odd vulnerabilities_24.html output

2020-04-04 Thread William A Rowe Jr
On Sat, Apr 4, 2020 at 11:27 AM William A Rowe Jr wrote: > On Sat, Apr 4, 2020 at 10:23 AM Daniel Ruggeri > wrote: > >> Hi, all; >>I'm not sure what mechanism is used to generate >> https://httpd.apache.org/security/vulnerabilities_24.html from >> >

Re: Odd vulnerabilities_24.html output

2020-04-04 Thread William A Rowe Jr
On Sat, Apr 4, 2020 at 10:23 AM Daniel Ruggeri wrote: > Hi, all; >I'm not sure what mechanism is used to generate > https://httpd.apache.org/security/vulnerabilities_24.html from > > https://svn.apache.org/repos/asf/httpd/site/trunk/content/security/vulnerabilities-ht

Odd vulnerabilities_24.html output

2020-04-04 Thread Daniel Ruggeri
Hi, all;    I'm not sure what mechanism is used to generate https://httpd.apache.org/security/vulnerabilities_24.html from https://svn.apache.org/repos/asf/httpd/site/trunk/content/security/vulnerabilities-httpd.xml, but an anomaly has been reported to me in response to the security announce

Re: svn commit: r33392 - in /release/httpd: Announcement2.4.html Announcement2.4.txt CURRENT-IS-2.4.38 CURRENT-IS-2.4.39

2019-04-02 Thread Ruediger Pluem
Added: >> release/httpd/CURRENT-IS-2.4.39 >> Removed: >> release/httpd/CURRENT-IS-2.4.38 >> Modified: >> release/httpd/Announcement2.4.html >> release/httpd/Announcement2.4.txt >> >> Modified: release/httpd/Announcement2.4.ht

Re: svn commit: r33392 - in /release/httpd: Announcement2.4.html Announcement2.4.txt CURRENT-IS-2.4.38 CURRENT-IS-2.4.39

2019-04-01 Thread Ruediger Pluem
ttpd/CURRENT-IS-2.4.38 > Modified: > release/httpd/Announcement2.4.html > release/httpd/Announcement2.4.txt > > Modified: release/httpd/Announcement2.4.html > == > --- release/httpd/Announcement2.4.html (orig

Re: Patches related to HTML output by Apache httpd itself

2019-01-23 Thread Andras Farkas
Ping again. This is a really simple patch. On Thu, Dec 20, 2018 at 12:26 AM Andras Farkas wrote: > > Ping. > https://bz.apache.org/bugzilla/show_bug.cgi?id=62989 > It's on the bugzilla too now.

Re: Patches related to HTML output by Apache httpd itself

2018-12-20 Thread Mario Colindres
Intibated Apache Source Pure On Wed, Dec 19, 2018, 9:27 PM Andras Farkas wrote: > Ping. > https://bz.apache.org/bugzilla/show_bug.cgi?id=62989 > It's on the bugzilla too now. >

Re: Patches related to HTML output by Apache httpd itself

2018-12-19 Thread Andras Farkas
Ping. https://bz.apache.org/bugzilla/show_bug.cgi?id=62989 It's on the bugzilla too now.

Re: Patches related to HTML output by Apache httpd itself

2018-12-06 Thread Andras Farkas
> stuff. > If I were to refactor the error messages, I'd be looking to take all remaining > actual HTML out of the server itself, and into documents (or templates) under > the control of the sysop. Invalid HTML is inherently wrong, and there's also no need to tell browse

Re: Patches related to HTML output by Apache httpd itself

2018-12-06 Thread Nick Kew
> On 6 Dec 2018, at 11:34, Andras Farkas wrote: > > Ping. > On Mon, Nov 26, 2018 at 4:08 AM Andras Farkas > wrote: >> >> Evening! >> >> I noticed that most of the time, when Apache httpd itself generates >> HTML output (like for 404 pages and

Re: Patches related to HTML output by Apache httpd itself

2018-12-06 Thread Andras Farkas
Ping. On Mon, Nov 26, 2018 at 4:08 AM Andras Farkas wrote: > > Evening! > > I noticed that most of the time, when Apache httpd itself generates > HTML output (like for 404 pages and autoindex pages) it uses ancient > HTML 2.0 and HTML 3.2 doctypes. > These 11 attached dif

Patches related to HTML output by Apache httpd itself

2018-11-26 Thread Andras Farkas
Evening! I noticed that most of the time, when Apache httpd itself generates HTML output (like for 404 pages and autoindex pages) it uses ancient HTML 2.0 and HTML 3.2 doctypes. These 11 attached diffs update those. The most important of the diffs is httpdh.diff I compiled and tested these diffs

Re: Content-Type / AddOutputFilterByType DEFLATE text/html

2017-08-08 Thread William A Rowe Jr
$curl, CURLOPT_HEADER, 1); > curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, 0); > curl_setopt($curl, CURLOPT_URL, $url); > curl_setopt($curl, CURLOPT_HTTPHEADER, $curl_header); > > Am 07.08.2017 um 11:12 schrieb Reindl Harald: > >> Hi >> >> AddOutputFilterByType DEF

Re: Content-Type / AddOutputFilterByType DEFLATE text/html

2017-08-07 Thread Reindl Harald
curl_setopt($curl, CURLOPT_HEADER, 1); curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($curl, CURLOPT_URL, $url); curl_setopt($curl, CURLOPT_HTTPHEADER, $curl_header); Am 07.08.2017 um 11:12 schrieb Reindl Harald: Hi AddOutputFilterByType DEFLATE text/html is this a bug or someh

Content-Type / AddOutputFilterByType DEFLATE text/html

2017-08-07 Thread Reindl Harald
Hi AddOutputFilterByType DEFLATE text/html is this a bug or somehow expected behavior that in case the "Content-Type" header also contains a charset mod_defalte don't work as expected which means in case of curl requests only static files are gzip compressed while PHP respon

Re: svn commit: r17757 - in /dev/httpd: Announcement2.2.html Announcement2.2.txt

2017-01-12 Thread William A Rowe Jr
ation is to call out "security defects and enhancements" or omit httpoxy from the primary announcement text > Modified: > dev/httpd/Announcement2.2.html > dev/httpd/Announcement2.2.txt The draft is at http://httpd.apache.org/dev/dist/Announcement2.2.html http://httpd.apa

Re: svn commit: r17517 - in /dev/httpd: Announcement2.4.html httpd_logo_wide_new.png

2016-12-21 Thread Luca Toscano
2016-12-21 19:20 GMT+01:00 Eric Covener : > On Wed, Dec 21, 2016 at 1:06 PM, Jacob Champion > wrote: > > On 12/21/2016 10:01 AM, jchamp...@apache.org wrote: > >> > >> Log: > >> 2.4.25: give the Announcement HTML a face-lift > >> > >> Mo

Re: svn commit: r17517 - in /dev/httpd: Announcement2.4.html httpd_logo_wide_new.png

2016-12-21 Thread Eric Covener
On Wed, Dec 21, 2016 at 1:06 PM, Jacob Champion wrote: > On 12/21/2016 10:01 AM, jchamp...@apache.org wrote: >> >> Log: >> 2.4.25: give the Announcement HTML a face-lift >> >> Move from HTML 3.2 into the brave new world of CSS. Add the new project >> logo a

Re: svn commit: r17517 - in /dev/httpd: Announcement2.4.html httpd_logo_wide_new.png

2016-12-21 Thread Jacob Champion
On 12/21/2016 10:01 AM, jchamp...@apache.org wrote: Log: 2.4.25: give the Announcement HTML a face-lift Move from HTML 3.2 into the brave new world of CSS. Add the new project logo and a date to the announcement. So, I was bold and checked in a facelift to the whole page when I added the new

Re: svn commit: r17503 - in /dev/httpd: Announcement2.4.html Announcement2.4.txt

2016-12-20 Thread William A Rowe Jr
welcomed >> >> Modified: >> dev/httpd/Announcement2.4.html >> dev/httpd/Announcement2.4.txt >> > > I'll take the Announcement live on the hour (30 min from now), anyone > who wants to edit, the path is a little unusual; > > https://dist.ap

Re: svn commit: r17503 - in /dev/httpd: Announcement2.4.html Announcement2.4.txt

2016-12-20 Thread William A Rowe Jr
On Tue, Dec 20, 2016 at 12:13 PM, wrote: > Author: wrowe > Date: Tue Dec 20 18:13:12 2016 > New Revision: 17503 > > Log: > Record security errata, edits in the next 45 minutes are most welcomed > > Modified: > dev/httpd/Announcement2.4.html > dev/httpd/An

Re: svn commit: r1750681 - in /httpd/httpd/branches/2.4.x: STATUS docs/manual/mod/mod_proxy_http2.html docs/manual/mod/mod_proxy_http2.html.en docs/manual/mod/mod_proxy_http2.xml.meta

2016-06-29 Thread André Malo
ttpd/httpd/branches/2.4.x/docs/manual/mod/mod_proxy_http2.html > httpd/httpd/branches/2.4.x/docs/manual/mod/mod_proxy_http2.html.en > httpd/httpd/branches/2.4.x/docs/manual/mod/mod_proxy_http2.xml.meta Huh? nd -- Das einzige, das einen Gebäudekollaps (oder auch einen thermon

HTML hyperlink tag disconnect during rewrite in mod_proxy_html

2016-01-05 Thread Scott Munson
nship with a table. After running through proxy, the resultant HTML always moves the child nodes of the hyperlink up to be a sibling of the hyperlink instead of remaining children. E.g. becomes Example appears below, although other flavors exist such as a hyperlink within a table text here bec

Re: Is mod_substitute effective on mod_autoindex-generated HTML?

2014-05-22 Thread Christophe JAILLET
syntax that looks like: >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> LoadModule substitute_module modules/mod_substitute.so LoadModule autoindex_module modules/mod_autoindex.so

Is mod_substitute effective on mod_autoindex-generated HTML?

2014-05-22 Thread Mikhail T.
Hello! I'm trying to make some substitutions on the HTML-output generated by mod_autoindex. However, things quietly do not work... Even the simplest directive: Substitute s/Parent/Father/ seems ignored -- and the browser is showing "Parent Directory" instead of "Fa

Re: [PATCH ASF bugzilla #56288] mod_proxy_html could rewrite URLs in HTML style attributes too

2014-03-20 Thread Micha Lenk
Hi, the patch was missing in my previous mail. See attachment. Regards, Micha On 19.03.2014 22:26, Micha Lenk wrote: Hi Apache developers, In HTML you can have tags that have a background image by providing a style attribute. E.g. this can be done by something fancy like this: http

[PATCH ASF bugzilla #56288] mod_proxy_html could rewrite URLs in HTML style attributes too

2014-03-19 Thread Micha Lenk
Hi Apache developers, In HTML you can have tags that have a background image by providing a style attribute. E.g. this can be done by something fancy like this: http://www.example.com/fancy-background.png) right 0px no-repeat; height:325px;"> Currently mod_proxy_html doesn'

Re: [PATCH] mod_proxy_html sometimes adds random characters to HTML pages smaller than 4 bytes

2014-03-19 Thread Micha Lenk
Hi, On 19.03.2014 21:19, Jim Jagielski wrote: It's always best, imo, to follow-up with a bugzilla entry with description and patch. Ok, this issue is now filed in ASF bugzilla as #56286. Regards, Micha

Re: [PATCH] mod_proxy_html deletes wrong data from HTML when meta http-equiv tag specifies Content-Type behind other meta http-equiv tag

2014-03-19 Thread Micha Lenk
Hi again, Err, #56287 that is. Regards, Micha On 19.03.2014 22:05, Micha Lenk wrote: Just for the records, I've just filed this issue in ASF bugzilla as issue #56286.

Re: [PATCH] mod_proxy_html deletes wrong data from HTML when meta http-equiv tag specifies Content-Type behind other meta http-equiv tag

2014-03-19 Thread Micha Lenk
SVN (best both, trunk and then backported to 2.4). This is something that I feel to owe the Apache httpd community. So, lets first start with a bug that lets mod_proxy_html delete the wrong data from HTML code when a "http-equiv" meta tag specifies a Content-Type behind any other &

Re: [PATCH] mod_proxy_html sometimes adds random characters to HTML pages smaller than 4 bytes

2014-03-19 Thread Jim Jagielski
It's always best, imo, to follow-up with a bugzilla entry with description and patch. Thx!! On Mar 19, 2014, at 3:58 PM, Micha Lenk wrote: > Hi Apache developers, > > next is a bug that causes mod_proxy_html to add some random characters (+html > code) to HTML pages, i

[PATCH] mod_proxy_html sometimes adds random characters to HTML pages smaller than 4 bytes

2014-03-19 Thread Micha Lenk
Hi Apache developers, next is a bug that causes mod_proxy_html to add some random characters (+html code) to HTML pages, if the document is smaller than 4 bytes. (Thomas, Ewald, this is issue #18378 in our Mantis). It looks like the output is from some kind of uninitialized memory. The added

[PATCH] mod_proxy_html deletes wrong data from HTML when meta http-equiv tag specifies Content-Type behind other meta http-equiv tag

2014-03-19 Thread Micha Lenk
a bug that lets mod_proxy_html delete the wrong data from HTML code when a "http-equiv" meta tag specifies a Content-Type behind any other "http-equiv" meta tag (Thomas, Ewald, this is issue #21648 in our Mantis). For better understanding of the issue, please consider the follo

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-09 Thread Reindl Harald
the next one with his vendetta i just *asked* consider post plain text nothing more Am 10.03.2014 00:32, schrieb Nick Edwards: > Truer words were never spoken about Harald Reindl, this person brings > trouble to every mailing list he joins > > postfix - banned read the history > fedora - modera

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-09 Thread Nick Edwards
Truer words were never spoken about Harald Reindl, this person brings trouble to every mailing list he joins postfix - banned fedora - moderation centos - moderation/banned roundcube - moderation dovecot - final warnings and they are just the lists I know of, and when moderated he is known to sen

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-09 Thread Eric Covener
On Sun, Mar 9, 2014 at 2:01 PM, Reindl Harald wrote: > > Am 08.03.2014 01:38, schrieb Noel Butler: >> This will be dealt with off list > > with the words below which are only a part of the off-list reply It should be kept off-list. Just stop.

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-09 Thread Reindl Harald
warning your the only one who will regret it >> stop your personal vendetta - the only one playing internet cop is you >> >> i have asked in a nice way to not post HTML and explained why >> the other person had no problem with my question / hin > Original-Nachricht

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-07 Thread Noel Butler
This will be dealt with off list On 08/03/2014 09:51, Reindl Harald wrote: > what exactly is your personal problem? > can you please post plaintext instead HTML to lists you did see the word "please"? >> for me such messages are unreadable after medical operations on

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-07 Thread Reindl Harald
what exactly is your personal problem? >> can you please post plaintext instead HTML to lists you did see the word "please"? >> for me such messages are unreadable after medical operations >> on both eyes because you override my MUA font settings you understood

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-07 Thread Noel Butler
e bylaws of this mailing list > > that use of HTML is something to apologize for? > > nearly any mailing-list has it written clear, some even reject HTML > and on some others you get warned by the owner (postfix as example) > > https://www.google.com/search?q=mailing+list+eti

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-07 Thread Noel Butler
On Fri, 2014-03-07 at 12:58 -0500, Mikhail T. wrote: > On 07.03.2014 12:28, Yann Ylavic wrote: > > > > > Sorry, this was posted from gmail... > > Is it written anywhere in the bylaws of this mailing list, that use of > HTML is something to apologize for? With all d

Re: Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-07 Thread Reindl Harald
Am 07.03.2014 18:58, schrieb Mikhail T.: > On 07.03.2014 12:28, Yann Ylavic wrote: >> Sorry, this was posted from gmail... > Is it written anywhere in the bylaws of this mailing list > that use of HTML is something to apologize for? nearly any mailing-list has it written clear, s

Use of HTML on mailing lists (Re: SO_REUSEPORT in the children processes)

2014-03-07 Thread Mikhail T.
On 07.03.2014 12:28, Yann Ylavic wrote: > Sorry, this was posted from gmail... Is it written anywhere in the bylaws of this mailing list, that use of HTML is something to apologize for? With all due sympathies to Reindl's medical condition, why must we -- in the second decade of the 21st

Re: svn commit: r1291829 - /httpd/site/trunk/docs/security/vulnerabilities_24.html

2012-02-21 Thread Jeff Trawick
On Tue, Feb 21, 2012 at 9:59 AM, wrote: > Author: trawick > Date: Tue Feb 21 14:59:07 2012 > New Revision: 1291829 > > URL: http://svn.apache.org/viewvc?rev=1291829&view=rev > Log: > generated file from r1291828 > > Added: >    httpd/site/trunk/docs/securit

Re: svn commit: r503 - in /dev/httpd: Announcement2.4.html Announcement2.4.txt

2012-02-21 Thread William A. Rowe Jr.
On 2/21/2012 3:26 AM, Rainer Jung wrote: >> - NOTE: Windows users may have problems with Apache httpd 2.4.1 and >> - SSL. As such, Apache 2.4.x is currently not recommended for >> - Windows servers. >> + NOTE to Windows users: AcceptFilter None has replaced >> DisableWin32Accept

Re: svn commit: r503 - in /dev/httpd: Announcement2.4.html Announcement2.4.txt

2012-02-21 Thread Rainer Jung
On 21.02.2012 09:44, wr...@apache.org wrote: Author: wrowe Date: Tue Feb 21 08:44:06 2012 New Revision: 503 Modified: dev/httpd/Announcement2.4.html dev/httpd/Announcement2.4.txt Modified: dev/httpd/Announcement2.4.html

Re: svn commit: r503 - in /dev/httpd: Announcement2.4.html Announcement2.4.txt

2012-02-21 Thread William A. Rowe Jr.
fic than Jim's first draft. > > Modified: > dev/httpd/Announcement2.4.html > dev/httpd/Announcement2.4.txt > > Modified: dev/httpd/Announcement2.4.html > ====== > --- dev/httpd/Announce

Re: how to parse html content in handler

2011-03-25 Thread MK
On Fri, 25 Mar 2011 10:19:43 -0400 Joshua Marantz wrote: > mod_pagespeed's event-driven HTML parser is open source, and is > written in C++: There are quite a few around in C++, Boost also has (at least) one. -- "Enthusiasm is not the enemy of the intellect." (said

Re: how to parse html content in handler

2011-03-25 Thread MK
On Thu, 24 Mar 2011 22:58:07 +0800 (CST) "Whut Jia" wrote: > Hi, > Thank you! > But I want to parse a jsp page in my handler.How can I do it?? I've never used .jps but it looks to me like all the processing instructions are in the form <% instruction %>. If that's the case, the simple parser I

Re: svn commit: r981498 - in /httpd/site/trunk: docs/security/vulnerabilities-oval.xml docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities-httpd.xml

2010-08-02 Thread Rainer Jung
On 02.08.2010 15:47, Joe Orton wrote: On Mon, Aug 02, 2010 at 03:33:45PM +0200, Rainer Jung wrote: --- httpd/site/trunk/docs/security/vulnerabilities-oval.xml (original) +++ httpd/site/trunk/docs/security/vulnerabilities-oval.xml Mon Aug 2 13:03:04 2010 @@ -714,6 +714,31 @@ to cross-site scrip

Re: svn commit: r981498 - in /httpd/site/trunk: docs/security/vulnerabilities-oval.xml docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities-httpd.xml

2010-08-02 Thread Joe Orton
On Mon, Aug 02, 2010 at 03:33:45PM +0200, Rainer Jung wrote: > >--- httpd/site/trunk/docs/security/vulnerabilities-oval.xml (original) > >+++ httpd/site/trunk/docs/security/vulnerabilities-oval.xml Mon Aug 2 > >13:03:04 2010 > >@@ -714,6 +714,31 @@ to cross-site scripting (XSS) attacks. > > >

Re: svn commit: r981498 - in /httpd/site/trunk: docs/security/vulnerabilities-oval.xml docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities-httpd.xml

2010-08-02 Thread Rainer Jung
.xml httpd/site/trunk/docs/security/vulnerabilities_22.html httpd/site/trunk/xdocs/security/vulnerabilities-httpd.xml Modified: httpd/site/trunk/docs/security/vulnerabilities-oval.xml URL: http://svn.apache.org/viewvc/httpd/site/trunk/docs/security/vulnerabilities-oval.xml?rev=981498&r1=9

Re: svn commit: r920084 - in /httpd/site/trunk: docs/security/vulnerabilities-oval.xml docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities-httpd.xml

2010-03-07 Thread William A. Rowe Jr.
On 3/7/2010 2:12 PM, m...@apache.org wrote: > Author: mjc > Date: Sun Mar 7 20:12:21 2010 > New Revision: 920084 > > URL: http://svn.apache.org/viewvc?rev=920084&view=rev > Log: > Just make it clear this is a flaw only affecting Windows > installations that use mod_isapi. These entries need a bi

Re: svn commit: r94 - in /dev/httpd: Announcement2.2.html Announcement2.2.txt

2010-03-06 Thread William A. Rowe Jr.
On 3/6/2010 6:52 AM, Jeff Trawick wrote: >> --- dev/httpd/Announcement2.2.html (original) >> +++ dev/httpd/Announcement2.2.html Sat Mar 6 07:41:31 2010 >> @@ -68,7 +68,8 @@ >>APR-util library version 1.3.9, bundled with the tar and zip >> distributions. >

Re: svn commit: r94 - in /dev/httpd: Announcement2.2.html Announcement2.2.txt

2010-03-06 Thread Jeff Trawick
On Sat, Mar 6, 2010 at 7:41 AM, wrote: > Author: trawick > Date: Sat Mar  6 07:41:31 2010 > New Revision: 94 > > Log: > minor tweaks, especially to mention continued compatibility with APR 1.3 > > Modified: >    dev/httpd/Announcement2.2.html >    dev/httpd/Announc

Re: svn commit: r821989 - in /httpd/site/trunk: dist/Announcement2.2.html dist/Announcement2.2.txt dist/binaries/win32/README.html docs/doap.rdf docs/download.html docs/index.html xdocs/doap.rdf xdo

2009-10-05 Thread Graham Leggett
Jeff Trawick wrote: > The security aspect of the bundling of APR and APR-util needs to be > tweaked. Does this look right? It does, thanks for taking a look. Regards, Graham -- smime.p7s Description: S/MIME Cryptographic Signature

Re: svn commit: r821989 - in /httpd/site/trunk: dist/Announcement2.2.html dist/Announcement2.2.txt dist/binaries/win32/README.html docs/doap.rdf docs/download.html docs/index.html xdocs/doap.rdf xdo

2009-10-05 Thread Jeff Trawick
re the announcement for httpd v2.2.14. > > SvnPubSub works great :) > > Would it be possible for someone to eyeball these changes and make sure > I didn't miss anything out or break anything? > The security aspect of the bundling of APR and APR-util ne

Re: svn commit: r821989 - in /httpd/site/trunk: dist/Announcement2.2.html dist/Announcement2.2.txt dist/binaries/win32/README.html docs/doap.rdf docs/download.html docs/index.html xdocs/doap.rdf xdocs

2009-10-05 Thread Graham Leggett
minf...@apache.org wrote: > Author: minfrin > Date: Mon Oct 5 20:11:21 2009 > New Revision: 821989 > > URL: http://svn.apache.org/viewvc?rev=821989&view=rev > Log: > Prepare the announcement for httpd v2.2.14. SvnPubSub works great :) Would it be possible for someone to eyeball these changes a

Re: svn commit: r802411 - in /httpd/site/trunk: build.props dist/Announcement2.2.html dist/Announcement2.2.txt dist/binaries/win32/README.html xdocs/doap.rdf xdocs/download.xml

2009-08-09 Thread Bob Ionescu
2009/8/8 : > Author: wrowe > Date: Sat Aug 8 16:09:45 2009 > New Revision: 802411 > > URL: http://svn.apache.org/viewvc?rev=802411&view=rev > Log: > Prepare for release after 5 +1's no -1's. > > Modified: >httpd/site/trunk/build.props >

Re: svn commit: r802411 - in /httpd/site/trunk: build.props dist/Announcement2.2.html dist/Announcement2.2.txt dist/binaries/win32/README.html xdocs/doap.rdf xdocs/download.xml

2009-08-08 Thread Ruediger Pluem
ttpd/site/trunk/build.props > httpd/site/trunk/dist/Announcement2.2.html > httpd/site/trunk/dist/Announcement2.2.txt > httpd/site/trunk/dist/binaries/win32/README.html > httpd/site/trunk/xdocs/doap.rdf > httpd/site/trunk/xdocs/download.xml > > Modified: ht

Correction to BID 29112 "Apache Server HTML Injection and UTF-7 XSS Vulnerability"

2008-05-14 Thread William A. Rowe, Jr.
HTTP User and Desktop Security Communities; With respect to http://www.securityfocus.com/bid/29112 Per http://www.ietf.org/rfc/rfc2616.txt 3.7.1 Canonicalization and Text Defaults [...] The "charset" parameter is used with some media types to define the character set (section 3.4) of the

Re: [Fwd: Re: HTML request accesses my router]

2007-11-08 Thread William A. Rowe, Jr.
Eric, once a year, forwarding notices from [EMAIL PROTECTED] to [EMAIL PROTECTED] I completely screw up and let autocomplete pick up dev@ - I'm sorry this just occurred and want to be certain you are aware ASAP! Fortunately it does seem to be a local access junction, most router hardware will le

[Fwd: Re: HTML request accesses my router]

2007-11-08 Thread William A. Rowe, Jr.
/ignore - sorry for the noise. Original Message Subject: Re: HTML request accesses my router Date: Thu, 08 Nov 2007 19:17:59 -0500 From: Eric Maurier <[EMAIL PROTECTED]> Organization: Ross-Tech.com To: Apache Security Response Team <[EMAIL PROTECTED]> CC: Uwe

[Fwd: svn commit: r413981 - in /httpd/httpd/dist: Announcement1.3.html Announcement1.3.txt]

2006-06-13 Thread William A. Rowe, Jr.
Question; it was fairly clear folks were fine with removing 1.3 binaries (still hooking things up correctly as I type) for Win32. It seems rational to drop Netware and OS2, but I'm not a stakeholder of either. It's up to you maintainers if you feel we should keep shipping netware and OS2 Apache 1

Re: svn commit: r398494 - in /httpd/site/trunk: docs/security/vulnerabilities_13.html docs/security/vulnerabilities_20.html docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities_22.xml

2006-05-01 Thread Paul Querna
Mark J Cox wrote: >> This killed the list of vulnerabilities for all versions. Was this intended? >> And if yes, where can they be found now? > > Must be someone with bad java foo, fixing. > Er. ya. It wasn't my intention to break stuff, I just ran build.sh and it kept saying it wanted to do thi

Re: svn commit: r398494 - in /httpd/site/trunk: docs/security/vulnerabilities_13.html docs/security/vulnerabilities_20.html docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities_22.xml

2006-05-01 Thread Mark J Cox
> This killed the list of vulnerabilities for all versions. Was this intended? > And if yes, where can they be found now? Must be someone with bad java foo, fixing. Mark -- Mark J Cox | www.awe.com/mark

Re: svn commit: r398494 - in /httpd/site/trunk: docs/security/vulnerabilities_13.html docs/security/vulnerabilities_20.html docs/security/vulnerabilities_22.html xdocs/security/vulnerabilities_22.xml

2006-05-01 Thread Ruediger Pluem
On 05/01/2006 03:32 AM, [EMAIL PROTECTED] wrote: > Author: pquerna > Date: Sun Apr 30 18:32:18 2006 > New Revision: 398494 > > URL: http://svn.apache.org/viewcvs?rev=398494&view=rev > Log: > rebuild all. > > Modified: > httpd/site/trunk/docs/security/v

Re: svn commit: r392234 - in /httpd/site/trunk: docs/security/vulnerabilities_13.html xdocs/security/vulnerabilities-httpd.xml

2006-04-07 Thread William A. Rowe, Jr.
[EMAIL PROTECTED] wrote: Author: mjc Date: Fri Apr 7 02:58:47 2006 New Revision: 392234 URL: http://svn.apache.org/viewcvs?rev=392234&view=rev Log: Revert revision 392230. wrowe correctly points out that cve-2005-2088 didn't affect apache 1.3, and indeed I've mailed people that thought it di

Re: svn commit: r392230 - in /httpd/site/trunk: docs/security/vulnerabilities_13.html xdocs/security/vulnerabilities-httpd.xml

2006-04-07 Thread Mark J Cox
> 1.3 was UNAFFECTED Yes, indeed it was me that insisted that this didn't affect 1.3, I'll revert it :) Cheers, Mark

Re: svn commit: r392230 - in /httpd/site/trunk: docs/security/vulnerabilities_13.html xdocs/security/vulnerabilities-httpd.xml

2006-04-07 Thread William A. Rowe, Jr.
PROTECTED] wrote: Author: mjc Date: Fri Apr 7 02:39:36 2006 New Revision: 392230 URL: http://svn.apache.org/viewcvs?rev=392230&view=rev Log: From: Mike O'Connor Subject: Apacheweek security minor addition, I think I think http://httpd.apache.org/security/vulnerabilities_13.html should

Re: html parsing filter

2006-03-30 Thread Joachim Zobel
Am Mittwoch, den 29.03.2006, 00:16 -0500 schrieb Miso G.: > And as far as caching those images/links goes, I need them to be > pre-loaded for the user that is viewing the html page, not the other > users after him. Sort of like pre-fetching the links in advance, in case > the use

Re: html parsing filter

2006-03-28 Thread Miso G.
Ok, I'll look into those modules mentioned, thanks! And as far as caching those images/links goes, I need them to be pre-loaded for the user that is viewing the html page, not the other users after him. Sort of like pre-fetching the links in advance, in case the user decides to visit a

Re: html parsing filter

2006-03-26 Thread Nick Kew
On Monday 27 March 2006 00:01, Miso G. wrote: > Has anyone created a filter that parses html for let's say links to > images only already? Or are there any examples on the web of similar > filters (if so, where?). mod_accessibility, mod_proxy_html, mod_publisher all filter HTML an

html parsing filter

2006-03-26 Thread Miso G.
Has anyone created a filter that parses html for let's say links to images only already? Or are there any examples on the web of similar filters (if so, where?). What I am trying to achieve is create a filter/module that will gather all the links to images from html pages before the

Re: svn commit: r279680 - in /httpd/httpd/dist: Announcement21.html Announcement21.txt

2005-09-12 Thread William A. Rowe, Jr.
I read the announce today... not quite sure what part of the message below wasn't clear, but no, the compiled httpd.exe simply won't work on any flavor of Win32 I'm aware of. William A. Rowe, Jr. wrote: URL: http://svn.apache.org/viewcvs/httpd/httpd/dist/Announcement21.txt?rev=279680&r1=279679&

Re: svn commit: r279680 - in /httpd/httpd/dist: Announcement21.html Announcement21.txt

2005-09-08 Thread William A. Rowe, Jr.
URL: http://svn.apache.org/viewcvs/httpd/httpd/dist/Announcement21.txt?rev=279680&r1=279679&r2=279680&view=diff == --- httpd/httpd/dist/Announcement21.txt (original) +++ httpd/httpd/dist/Announcement21.txt Thu Sep 8 17:5

Error with Apache 1.x web servers while posting data from one HTML page to another HTML page

2005-02-23 Thread Manoj Jain
Title: Error with Apache 1.x web servers while posting data from one HTML page to another HTML page Hi I have two HTML pages hosted on Apache 1.3.33 web server on Solaris. The first HTML page have some text fields and a submit button. On clicking the button this HTML page should posts

Error with Apache 1.x web servers while posting data from one HTML page to another HTML page

2005-02-22 Thread Rahul Kohli
Hi I have two HTML pages hosted on Apache 1.3.33 web server on Solaris. The first HTML page have some text fields and a submit button. On clicking the button this HTML page should posts the data to second HTML page. This has been done by specifying path for the second HTML page in the action

FW: svn commit: r106690 - in httpd/httpd/trunk: . srclib/pcre srclib/pcre/doc srclib/pcre/doc/html srclib/pcre/testdata

2004-11-26 Thread Brian Pane
ew=rev&rev=106690 Log: Upgraded the copy of PCRE within srclib/pcre to version 5.0 Added: httpd/httpd/trunk/srclib/pcre/doc/html/ - copied from r106688, httpd/httpd/vendor/pcre/5.0/doc/html/ httpd/httpd/trunk/srclib/pcre/doc/html/index.html - copied unchanged from r106688, httpd/httpd/v

Re: cvs commit: httpd-2.0/docs/manual new_features_2_2.html new_features_2_2.html.en new_features_2_2.xml new_features_2_2.xml.meta

2004-11-08 Thread William A. Rowe, Jr.
At 04:49 PM 11/7/2004, André Malo wrote: >* "Justin Erenkrantz" <[EMAIL PROTECTED]> wrote: > > >Well, but it's still the 2.1 branch with 2.1 docs (docs-2.1/). And, of course, >once tagged and released (as alpha, beta, whatever) it *is* public. Though not >stable. That's a difference :) That's your

Re: suggestion: strip comments from served html pages

2004-11-07 Thread Nick Kew
On Sun, 7 Nov 2004, [ISO-8859-15] André Malo wrote: > * Nick Kew <[EMAIL PROTECTED]> wrote: > > > BTW, the "what is a comment" problem is easier than it looks, as both > >

Re: cvs commit: httpd-2.0/docs/manual new_features_2_2.html new_features_2_2.html.en new_features_2_2.xml new_features_2_2.xml.meta

2004-11-07 Thread =?ISO-8859-15?Q?Andr=E9?= Malo
* "Justin Erenkrantz" <[EMAIL PROTECTED]> wrote: > > * [EMAIL PROTECTED] wrote: > > > >> pquerna 2004/11/06 22:01:50 > >> > >> Added: docs/manual new_features_2_2.html > >> new_features_2_2.html.en > >>

Re: suggestion: strip comments from served html pages

2004-11-07 Thread =?ISO-8859-15?Q?Andr=E9?= Malo
* Nick Kew <[EMAIL PROTECTED]> wrote: > BTW, the "what is a comment" problem is easier than it looks, as both >

Re: cvs commit: httpd-2.0/docs/manual new_features_2_2.html new_features_2_2.html.en new_features_2_2.xml new_features_2_2.xml.meta

2004-11-07 Thread Justin Erenkrantz
> * [EMAIL PROTECTED] wrote: > >> pquerna 2004/11/06 22:01:50 >> >> Added: docs/manual new_features_2_2.html >> new_features_2_2.html.en >> new_features_2_2.xml new_features_2_2.xml.meta >> Log: >> First Swi

Re: cvs commit: httpd-2.0/docs/manual new_features_2_2.html new_features_2_2.html.en new_features_2_2.xml new_features_2_2.xml.meta

2004-11-07 Thread Paul Querna
André Malo wrote: * [EMAIL PROTECTED] wrote: pquerna 2004/11/06 22:01:50 Added: docs/manual new_features_2_2.html new_features_2_2.html.en new_features_2_2.xml new_features_2_2.xml.meta Log: First Swing at a 2.0 -> 2.2 New Features Document. As long as we j

Re: suggestion: strip comments from served html pages

2004-11-07 Thread Nick Kew
strates that there is a demand for byte count reduction. mod_deflate uses a great deal more CPU, and achieves a great deal more savings, than any of the above. > I mean really, how much bandwidth > from *html* are we talking about? Compared to images? If you start > parsing the h

Re: suggestion: strip comments from served html pages

2004-11-07 Thread Cliff Woolley
blem (assuming that the "what's a comment and what isn't" problem is solvable) is that this kind of parsing takes a disproportionately large amount of CPU time with respect to the amount of network bandwidth it saves. I mean really, how much bandwidth from *html* are we talkin

Re: suggestion: strip comments from served html pages

2004-11-07 Thread Nick Kew
On Sun, 7 Nov 2004, Tobias Skytte wrote: Why not introduce and option to remove the > comments from the served file? You have that option from mod_xmlns, mod_proxy_html or mod_publisher, to name but three. Along with caveats about why it's not necessarily a good idea. -- Nick Kew

Re: suggestion: strip comments from served html pages

2004-11-07 Thread =?ISO-8859-15?Q?Andr=E9?= Malo
* "Tobias Skytte" <[EMAIL PROTECTED]> wrote: > Many webpages include alot of comments in the html code. Sometimes this > can me more than 50% of the file! At the same time the internet is getting > more and more congested. Why not introduce and option to remove

suggestion: strip comments from served html pages

2004-11-07 Thread Tobias Skytte
Hi, Many webpages include alot of comments in the html code. Sometimes this can me more than 50% of the file! At the same time the internet is getting more and more congested. Why not introduce and option to remove the comments from the served file? The person web-browsing any given site has

Re: cvs commit: httpd-2.0/docs/manual new_features_2_2.html new_features_2_2.html.en new_features_2_2.xml new_features_2_2.xml.meta

2004-11-07 Thread =?ISO-8859-15?Q?Andr=E9?= Malo
* [EMAIL PROTECTED] wrote: > pquerna 2004/11/06 22:01:50 > > Added: docs/manual new_features_2_2.html new_features_2_2.html.en > new_features_2_2.xml new_features_2_2.xml.meta > Log: > First Swing at a 2.0 -> 2.2 New Features Document

Re: Regeneration of html version of manual from xml

2004-10-15 Thread Hiroaki KAWAI
Please see http://httpd.apache.org/docs-project/docsformat.html. > Hi all, > > does anybody know how to regenerate the html version of the manual once I made > changes to the xml sources of > the manual? > > Thanks in advance > > R

Re: Regeneration of html version of manual from xml

2004-10-14 Thread André Malo
* [EMAIL PROTECTED] (Rüdiger Plüm) wrote: > Hi all, > > does anybody know how to regenerate the html version of the manual once I > made changes to the xml sources of the manual? Sure. See <http://httpd.apache.org/docs-project/docsformat.html>. If you have questions, jus

Regeneration of html version of manual from xml

2004-10-14 Thread Rüdiger Plüm
Hi all, does anybody know how to regenerate the html version of the manual once I made changes to the xml sources of the manual? Thanks in advance Rüdiger

html Parser...

2004-09-09 Thread Manos Moschous
Hi, I would like to use an html Parser in my apache module. Is there any well-known html parser to do this..? Do i need to recompile the apache web server in order to use this parser...? I found the old/net/libxml2/HTMLparser.c, what am i have to do to expand the apache web server...(recompile

[AIX 4.3.3] perl 5.6.1 + mod_perl 1.27 + apache 1.27 + libapreq 1.2 + HTML::Mason1.22 OK

2003-08-25 Thread Jose . auguste-etienne
, the .exp file being the httpd.exp I got the clue from http://www.mail-archive.com/[EMAIL PROTECTED]/msg34607.html so I try to build with perl Makefile.PL \ APACHE_SRC=../apache_1.3.27/src \ DO_HTTPD=1 \ USE_APACI=1 \ EVERYTHING=1 \ APACI_ARGS='--enable-module=so&#x

Re: How can I display .html files in the /cgi-bin directory...

2003-06-20 Thread Eric Cholet
Patrick Lam wrote: Dear all: I have the following lines in my httpd.conf file: - ScriptAlias /cgi-bin/ "/usr/local/cgi-bin/" Options +ExecCGI AllowOverride All -- However, I happen to have some .html files inside the /cgi-bin/

RE: How can I display .html files in the /cgi-bin directory...

2003-06-20 Thread Rahul Kohli
Patrick,   The cgi-bin directory is meant for scripts by default bcoz of the setting mentioned in httpd.conf. The default document root is /htdocs if you place the html files in this directory you can view them thru browser using the URL: http://servername:port/my.html   my.html is your

How can I display .html files in the /cgi-bin directory...

2003-06-20 Thread Patrick Lam
Dear all:   I have the following lines in my httpd.conf file:   - ScriptAlias /cgi-bin/ “/usr/local/cgi-bin/”       Options +ExecCGI     AllowOverride All --   However, I happen to have some .html files inside the /cgi-bin

Fwd: cvs commit: httpd-dist Announcement2.html Announcement2.txt

2003-03-31 Thread William A. Rowe, Jr.
Announcement to go out tommorow, after the mirrors have caught up. Thanks all, glad to hear the success stories, and hopefully we will have a cleaner binbuild script to work from this coming 2.0.46 release :-) Bill >wrowe 2003/03/31 23:40:19 > > Modified:.Announcem

  1   2   >