Transaction names in post Uris webdav
From: Bert Huijben <rhuijben_at_sharpsvn.net>
Date: Thu, 5 Feb 2009 16:04:08 +0100
[I sent this mail to the dev list; not the security list... as this part
Hi,
Our webdav implementation creates a public Uri to communicate over when
Anyway, in HTTPv1 we generated a UUID and used that as the public
For HTTPv2 the decision was made to no longer create a generated UUID ->
This might introduce a security problem, as it is certainly possible to
I don't know our webdav protocol and its emplementation well enough to
The attack vector I'm afraid of is:
Lets assume I know UserX is working on the WC library ...
Eventually UserX commits his transaction, but he commits deprecated.c
So in this case I can changed his transaction, without any trace in the
Is this a realistic attack?
I surely hope it isn't...
Thanks,
Bert
------------------------------------------------------
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.