LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > SSI: Garbage (leaked data) after date w/ time format

Reply
 
Thread Tools Display Modes
  #1  
Old 03-19-2010, 09:18 AM
AndrewT AndrewT is offline
Senior Member
 
Join Date: Jan 2010
Posts: 66
Default SSI: Garbage (leaked data) after date w/ time format

Using:

Code:
<!--#config timefmt="%A, %B %d"--><!--#echo var="DATE_LOCAL"-->
Is displaying something like:

Code:
Friday, March 19ef="bible/index.shtml">Join us in reading t4T}
It appears that data from other requests is being tacked on to the end. Refreshing the page results in new data at the end. Without the time format the date displays normally but obviously not in the desired format.

Edit: this is on 4.0.13

Edit 2: You may have trouble duplicating the problem on a low traffic server. Our test server does not have this problem but it also has no real traffic. I've tested this on multiple live servers and the problem exists as described in all cases.

Last edited by AndrewT; 03-19-2010 at 09:28 AM..
Reply With Quote
  #2  
Old 03-20-2010, 10:42 AM
NayBore NayBore is offline
New Member
 
Join Date: Mar 2010
Posts: 4
Default Leaking Private Data

I have also observed this problem with the Litespeed drop-in for Apache.

This appears to be a very serious PUBLIC leak of
any data that is being piped to std-out,
whether it is from a secure folder or not,
and whether or not it is encrypted.

Please advise with a patch, either to kill, or to repair this process.

Thanks very much.
Reply With Quote
  #3  
Old 03-20-2010, 09:55 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,585
Fix will be in 4.0.14 release.
Reply With Quote
  #4  
Old 03-21-2010, 07:38 AM
AndrewT AndrewT is offline
Senior Member
 
Join Date: Jan 2010
Posts: 66
When can we expect 4.0.14?
Reply With Quote
  #5  
Old 03-31-2010, 08:20 PM
NayBore NayBore is offline
New Member
 
Join Date: Mar 2010
Posts: 4
Default Over 300 Hours Unpatched

Several dozens of websites are are exposed to this exploit folks.

I am watching material from SECURE FOLDERS
being piped into the wild over a Litespeed http server, gang...

I need a kill switch, please.

This open-source one is looking good:
httpd.apache.org
Reply With Quote
  #6  
Old 04-01-2010, 09:01 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,585
4.0.14 build will be available tomorrow, you can do a manual update.
Reply With Quote
  #7  
Old 04-02-2010, 10:43 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,585
4.0.14 package is available now, just change version number in the download link to get it.
Reply With Quote
  #8  
Old 04-03-2010, 11:46 AM
NayBore NayBore is offline
New Member
 
Join Date: Mar 2010
Posts: 4
Default Isolated Treatment For Whiners

Quote:
Originally Posted by mistwang View Post
4.0.14 package is available now,
just change version number in the download link to get it.
I can NOT morally pursue this change
until the link becomes PUBLIC.

Security shuns preferential treatment.

That's very generous, just the same. Thank you.

500+ hours.... and ticking.
Reply With Quote
  #9  
Old 04-03-2010, 04:22 PM
ffeingol ffeingol is offline
Senior Member
 
Join Date: Jul 2007
Location: /dev/null
Posts: 290
I think this is pretty 'typical' LSWS treatment. 1st they put the new package up (but not links) for early adopters to test. After that they update the download links. Finally, after the upload link have been out a bit the push it out via the auto-upload.
Reply With Quote
  #10  
Old 04-29-2010, 01:13 AM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
Quote:
Originally Posted by NayBore View Post
...Security shuns preferential treatment.
Tell that to the Secret Service.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 09:55 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.