Production sites running a stock Zope are vulnerable to abuse of their 
server if they have not removed the 'Examples' folder.  For example, 
anyone could use http://notcarefulenough.com/Examples/FileLibrary as a 
warez repository.

I propose changing the 'View' permission on the entire folder to 
'Manager'-only to protect some of us from ourselves ;-)

Any objections?

seb



_______________________________________________
Zope-Dev maillist  -  [EMAIL PROTECTED]
http://lists.zope.org/mailman/listinfo/zope-dev
**  No cross posts or HTML encoding!  **
(Related lists - 
 http://lists.zope.org/mailman/listinfo/zope-announce
 http://lists.zope.org/mailman/listinfo/zope )

Reply via email to