Re: [xml-dev] XInclude: security risk 1

From
Miles Sabin <>
To
Date
2002-10-26T18:16:57Z
ID
<>
Thread
Re: [xml-dev] XInclude: security risk 1
Simon St.Laurent wrote,
> It reminds me a bit of the issues that David Megginson raised back at
> XTech 2000:
> http://www.xml.com/pub/a/2000/02/xtech/megginson.html
>
> I can't find David's original slides,

You mean these?

  http://www.megginson.com/ugly/slides/slide0001.html

There's also this thread of DMs on traffic analysis, 

  http://lists.xml.org/archives/xml-dev/200101/msg00057.html

which is related. And a little while ago I suggested this,

  http://lists.xml.org/archives/xml-dev/200206/msg00247.html

which does similar firewall penetration tricks as ERHs example, only 
without XInclude, just a parser which retrieves external entities.

Cheers,


Miles