Re: mod_proxy_html not working when using carriage returns

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, 21 Feb 2013 14:27:53 +0100
Krist van Besien <krist.vanbesien@xxxxxxxxx> wrote:

> > The second one has a CR right after href definition, and as a result
> > mod_proxy_html can't convert it. I would like to ask if someone knows a way
> > to let mod_proxy_html understand how to interpret that CR, or just a way to
> > remove that CR.
> 
> URIs can't contain a CR.

If we take the "liberal in what you accept" principle, that comes
out as a scheme called "<newline>https".  Defining a ProxyHTML rule
to match it would call for figuring out exactly what escaping
is involved, or more simply using a regexp match.

OTOH, this kind of liberality doesn't sit easily alongside security.
Accepting <newline>https as a synonym for https could be a slippery
slope.

-- 
Nick Kew

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx



[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux