Re: Security issue

Hi Rusty

On Aug 13, 2007, at 05:36 , Rusty Burchfield wrote:

> The following w3 validation server is allowing private IP addresses.
> 133.27.228.132
>
> For example:
> http://133.27.228.132/check?uri=http%3A%2F%2F0.0.0.0
> http://133.27.228.132/check?uri=http%3A%2F%2F0.0.0.0%3A22

Thanks for the heads-up, I fixed the configuration bit to disallow  
access to private IPs.
There was little security risk to it, as this host is not on a  
private network anyway, but it's better to have a consistent  
configuration with the other validator servers.

Thank you.
-- 
olivier

Received on Monday, 13 August 2007 05:34:45 UTC