Return-Path: Delivered-To: apmail-tomcat-dev-archive@www.apache.org Received: (qmail 2119 invoked from network); 1 Dec 2005 19:19:09 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (209.237.227.199) by minotaur.apache.org with SMTP; 1 Dec 2005 19:19:09 -0000 Received: (qmail 51553 invoked by uid 500); 1 Dec 2005 19:19:01 -0000 Delivered-To: apmail-tomcat-dev-archive@tomcat.apache.org Received: (qmail 51512 invoked by uid 500); 1 Dec 2005 19:19:01 -0000 Mailing-List: contact dev-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Developers List" Delivered-To: mailing list dev@tomcat.apache.org Received: (qmail 51501 invoked by uid 99); 1 Dec 2005 19:19:01 -0000 Received: from asf.osuosl.org (HELO asf.osuosl.org) (140.211.166.49) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 01 Dec 2005 11:19:01 -0800 X-ASF-Spam-Status: No, hits=0.0 required=10.0 tests= X-Spam-Check-By: apache.org Received-SPF: neutral (asf.osuosl.org: local policy) Received: from [193.252.22.156] (HELO smtp3.freeserve.com) (193.252.22.156) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 01 Dec 2005 11:20:27 -0800 Received: from me-wanadoo.net (localhost [127.0.0.1]) by mwinf3213.me.freeserve.com (SMTP Server) with ESMTP id 7A4EBB000096 for ; Thu, 1 Dec 2005 20:18:36 +0100 (CET) Received: from [192.168.0.2] (user-3436.l4.c1.dsl.pol.co.uk [81.77.237.108]) by mwinf3213.me.freeserve.com (SMTP Server) with ESMTP id 5FEFFB00009E for ; Thu, 1 Dec 2005 20:18:36 +0100 (CET) X-ME-UUID: 20051201191836394.5FEFFB00009E@mwinf3213.me.freeserve.com Message-ID: <438F4C8B.3040208@apache.org> Date: Thu, 01 Dec 2005 19:18:35 +0000 From: Mark Thomas User-Agent: Mozilla Thunderbird 1.0.6 (Windows/20050716) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Tomcat Developers List Subject: Re: directory listings References: <1133385668.32340.74.camel@planitia.boston.redhat.com> <438E549B.4080800@joedog.org> In-Reply-To: <438E549B.4080800@joedog.org> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Checked: Checked by ClamAV on apache.org X-Spam-Rating: minotaur.apache.org 1.6.2 0/1000/N Tim Funk wrote: > It looks like this issue only occurs when the XSLT transformation is > done on the directory listing. Which is not an out of box configuration > so there is no worry for DOS (in case anyone is wondering). Actually, there is an issue here without the XSLT. This is why directory listing is now disabled by default. See http://marc.theaimsgroup.com/?l=tomcat-dev&m=113148731122439&w=2 Mark --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org For additional commands, e-mail: dev-help@tomcat.apache.org