Ticket #59 (new bugs)

Opened 12 years ago

Last modified 12 years ago

root directory exposed through srm (#2550)

Reported by: patrick Owned by: litvinse
Priority: major Milestone: 1.8.0-16
Component: srm Keywords:
Cc: Sub Version:

Description

Through my srm client (which calls srmLs) I am able to list the root directory of the srm host:

[cameron@hyper] cli> ./ngls srm://srm.ndgf.org var boot tmp etc media cdrom lib ...

Although I cannot list any of these directories except pnfs, I think this is a potential security risk. Interestingly, when I use the fullDetailedListing option, it behaves as it should and I only see the pnfs directory. I don't think it is a configuration issue, I see this at all T1 dcache sites, eg

Change History

comment:1 Changed 12 years ago by patrick

  • Owner changed from patrick to omsynge
  • Milestone changed from 1.8.0-12-patch7 to 1.8.0-13

comment:2 Changed 12 years ago by patrick

  • Owner changed from omsynge to litvinse

comment:3 Changed 12 years ago by patrick

  • Owner changed from litvinse to patrick
  • Status changed from new to assigned

comment:4 Changed 12 years ago by patrick

  • Owner changed from patrick to litvinse
  • Status changed from assigned to new

comment:5 Changed 12 years ago by patrick

  • Milestone changed from 1.8.0-13 to 1.8.0-14

comment:6 Changed 12 years ago by tigran

  • Milestone changed from 1.8.0-14 to 1.8.0-15

comment:7 Changed 12 years ago by patrick

  • Milestone changed from 1.8.0-15 to 1.8.0-16
Note: See TracTickets for help on using tickets.