Edgewall Software
Modify

Opened 13 years ago

Closed 12 years ago

#5450 closed defect (fixed)

administrator cannot disable hdfdump

Reported by: quasistoic Owned by: Alec Thomas
Priority: high Milestone: 0.11
Component: general Version: devel
Severity: major Keywords: hdfdump trac-admin
Cc: Branch:
Release Notes:
API Changes:

Description

From as far back as revision 2078 to the time of this posting, there's been a FIXME note in source:/trunk/trac/web/api.py mentioning that administrators should be able to disable hdfdumps.

As far as I can tell, this issue was first brought up back in comment:ticket:51:6 but there was never any followup.

I do find it disturbing that anyone can visit any installation of trac, and regardless of the permissions afforded to the anonymous user, can append ?hdfdump=1 to obtain a good amount of sensitive information. http://trac.edgewall.org/wiki/?hdfdump=1

Attachments (0)

Change History (6)

comment:1 by quasistoic, 13 years ago

I've found that by commenting out lines 326-329 in source:/trunk/trac/web/api.py@5556#L326 and altering the whitespace on line 330 appropriately, I can disable hdfdumps in the case of a permission error, which solves my problem at the moment, namely:
If I've removed all permissions granted to anonymous, I want to make sure that anonymous cannot execute an hdfdump.

Still, it would be useful to build an option into the trac.ini file or something.

comment:2 by Alec Thomas, 13 years ago

Resolution: fixed
Status: newclosed

Fixed in r5636. hdfdump now requires TRAC_ADMIN.

comment:3 by quasistoic, 13 years ago

Cc: trac-ticket@… removed

Excellent! Thanks for the swift response!

comment:4 by Alec Thomas, 12 years ago

Resolution: fixed
Status: closedreopened

comment:5 by Alec Thomas, 12 years ago

Milestone: 0.11
Owner: changed from Jonas Borgström to Alec Thomas
Status: reopenednew
Version: devel

comment:6 by Alec Thomas, 12 years ago

Resolution: fixed
Status: newclosed

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Alec Thomas.
The resolution will be deleted. Next status will be 'reopened'.
to as closed The owner will be changed from Alec Thomas to the specified user.

Add Comment


E-mail address and name can be saved in the Preferences .
 
Note: See TracTickets for help on using tickets.