An idea for rewriting AUR web-interface

Hi
I just checkout the aur.git, and i guess it's better to rewrite it in other technologies for better maintaining/features/bug-fixing and implementing other enhancement.
For example nowadays web-applications shoulda be totally safe against XSS/CRSF, but couple of days ago aur experienced some XSS vulnerabilities, and so on..
I'm not talking about the code or code styling or something no, those are fine. But something like php without any framework help, is totally disaster. also i'm not talking about using php-framework either
If any plan is on, i really like to know about it.
So what do you think ?
Last edited by Alir3z4 (2012-02-23 21:23:30)

Alir3z4 wrote:Hi
I just checkout the aur.git, and i guess it's better to rewrite it in other technologies for better maintaining/features/bug-fixing and implementing other enhancement.
For example nowadays web-applications shoulda be totally safe against XSS/CRSF, but couple of days ago aur experienced some XSS vulnerabilities, and so on..
I'm not talking about the code or code styling or something no, those are fine. But something like php without any framework help, is totally disaster. also i'm not talking about using php-framework either
If any plan is on, i really like to know about it.
So what do you think ?
"Should" be safe and "are" safe are extremely different. Tools like burpsuite and skipfish exist simply because csrf and xss vulnerabilities will always sneak in regardless of the framework you use. I suspect that you would be surprised at how many sites out there have numerous vulnerabilities. In particular, I'll point out that despite things like PCI compliance, banks are notorious for being years behind in terms of security.
Regardless, rewriting the aur comes up pretty often. Sadly, I can't liken it to duke nukem forever anymore, bit hopefully you get the point. I encourage you to prove me wrong...

Similar Messages

  • How to make a form for input in web interface builder

    Hi expert:
        How to make a form for input in web interface builder?I have already used it to do PS planning, but I don't know how to  draw lines and checkboxes . Thanks in advance.
    Allen

    WAD:
    Open the WAD and create a new template. On the left hand navigation you will have several Web Items available. Under 'Standard' you have 'Analysis' item. Pull that into your template to the right. Under the Properties tab you need to pick the query [form/layout] that you have built in Query Designer.
    You will also find other items such as Button group, Checkbox, drop down, list box etc available. Pick and drag into the template whatever it is you require. Lets say you want a button. Under the Properties tab select the 'Command' that you require. You could use standard commands that are available there. You could also define functions and commands that you require.
    Query Designer:
    Open the QD and drag the characteristics and key figures that you require into the rows and columns of the QD. You would need to specify restrictions under the Filter tab of the QD based on the granularity of data that you require. You would need to remember that the key figures need to be made Input Ready [do this by clicking on KF and on the planning tab select "change by user and planning functions"].
    This shouldgive you a start. After you've explored it yourself a bit we can discuss further and I can certainly provide you additional details/material on these areas.
    Srikant

  • Variable Selection For User in Web Interface for BPS

    Hi All,
    I've created a manual Input sheet in BPS0 to upload target sales. User need to select the month, plant and then enter the target amount for each category. Its working fine.
    Now I need to create web interface for user to upload the data every month. Using BPS_WB I've created the interface (with help of Wizard). I'm getting the input sheet. But I'm not able to get screen where user can select the parameters?
    How to get this? It should work like web report, where user select the report variables then execute. Only difference here is user will have to enter the data for selected variable.
    Thanks in advance.
    Regards: Gaurave

    Hi....add the variables to a folder along with the layout. Then create the web interface.

  • Setting up a password for a switch web interface?

    Hi,
    I am trying to figure out how to set up a username/password for this switch I have.
    it is a: Cisco WS-C2924M-XL
    It seems to be easy but I couldn't find out how to do it so far.
    Any help would be appreciated.. i just started working with this. thanks!

    Hi!
    Are you trying to enable and set username/password for accessing switch through the web-interface? I hope I understood you correctly.
    Firstly you need to enable the switch for web-interface.
    Enter this command --> ip http-server
    Then you can login using the username [admin] and the enable password.
    If you want to set some other username for this purpose, then enter this command --> username
    Then you can login using the username and the enable password. By default only level 15 access is enabled for the web-interface.
    For a lil more have a look at the following URL --> http://www.cisco.com/en/US/tech/tk59/technologies_configuration_example09186a0080178a51.shtml#local
    Hope this helps...
    Regards,
    AbhisheK
    Please rate all helpful posts!!!

  • Any ideas for an interactive database interface?

    Based on some user selected criteria, a VI gets a 2 dimensional array of strings from a database. What I would like to do is then associate a true/false value with each row in the 2D array which the user can check/uncheck to indicate they would like to get more information from the database related to that row of data. I haven't found any good ways to implement this. I would really like it to be a mouse click; not have the user type a string, like "yes" or "no".

    Make a 1-D array of booleans (you can use a boolean control, or a check box control from the Dialog Controls pallette). Put the 1-D array of booleans and the 2-D array of strings in a cluster. Adjust the size of the boolean control so that the boolean rows line up with the string rows. The user can click one of the boolean controls for the row he or she is interested in. To read which row the user checked, unbundle the boolean array from the cluster, then find the index of the row using the Search 1D Array function. You can use the Event Structure to determine when the user has clicked on a boolean control.

  • I need to download and run firefox 4 or 3 for a certain web interface. How do I get from 5 (current download) to an older version?

    How do I go back to an older version of Firefox in order to accurately run a needed website

    You're welcome.
    Please click the '''Solved It''' button next to the answer that answered or solved your Firefox support issue, '''''it appears when you are logged in''''', so this thread gets marked as '''Solved''' to help other users who may have this same problem.

  • What are Web Interfaces in Oracle apps

    Hi,
    This is GV Krishna, Oracle apps technical consultant.
    In my current project I will have to work on Web Interfaces.
    I am very well aware of Conversions and interfaces using Interfaces tables and APPI's.
    I do not have any basic idea on Web Interfaces so for.
    Could you please suggeset what is use of Web Interfaces and how they are diffirent from other Interfaces.
    How can I approch for learning Web Interfaces initially.
    Please do provide if you know any documents are healpfull links.
    Thanks & Regards,
    GV Krishna.

    Hi Krishna;
    Please check below note which could be helpful for your issue:
    How Can I Expose E-Business Suite Integration Interfaces as Web Services? [ID 782455.1]
    Allow SYSADMIN to Change Notification Preference for Users From Web Interface [ID 746255.1] << check referance part
    Regard
    Helios

  • Web interface displays via Portal using Mozilla or Firefox

    We have several web interfaces (BW-BPS) and have created iViews on our Portal (EPP 6.0). These iViews properly execute in IE 6.0.
    However, when we execute the BPS iViews using Mozilla or Firefox we see significant display discrepancies. For example, the web interface should display grid lines between the rows, but, we don't see them when running through the Portal using Mozilla or Firefox.
    We thought that the Web interfaces themselves may be the issue but they properly execute when run straight from BW in Mozilla 1.7.13.
    Can anyone help with this problem? Thanks,
    Bill

    Hello Bill,
    first of all please check the Product Availability Matrix. Not all browser versions are supported. http://service.sap.com/pam
    Some visual differences between the browsers can not be avoided since browsers just behave differently.
    If the browser is supported and it does not work correctly, please open a customer message.
    Regards,
    Marc
    SAP NetWeaver RIG

  • Graduation project: ideas for a web application

    Hello,
    I apologize for posting this topic in here but I just need ideas from more experienced developers, we are a group of 5 students in computer science department and we are required to make a graduation project for a 1 year perioed, we have an average experience in J2EE, JSP, struts and JSF and J2SE and we are required to make the project as a web application but we just couldn't find any new or interesting ideas all the web application are either blogs, emai/webmai, Content Management systems, Customer relationship management, ... but we are looking for a new ideas, we've been googling for more than a month now and we've already checked alot of posts in this forum for ideas. we just want to know what services people need from the internet that could be made as a web application. Thank you very much

    Rather than looking for a cool "theme" can you give some ideas of what you need to showcase in this application?
    Is it just a basic web application - ie slap a few data entry screens together into a screenflow, and do some calculations at the end
    Do you need to demonstrate knowledge of the technologies you mentioned (J2EE, JSP, struts, JSF...)
    Do you need to push the limits of the web interface?
    Do you need to "break new ground"
    Ajax is a useful thing to investigate and push the boundaries with.
    Or take a web application and make it multi platform - ie access it with a browser, via a mobile phone - see what you need to do to accomplish that.
    The only other idea would be to do some sort of game/simulation.
    Multi user obviously.
    eg a stockmarket sim, where you can log on to buy/sell shares. You also hook up your app to some XML feeds where it picks up the daily changes so you don't have to enter them manually.
    Will demonstrate both user interface, and back end functionality.
    Good luck,
    evnafets

  • ASA 5505 configured for WebVPN connecting to Citrix Web Interface

    ASA 5505 configured for WebVPN connecting to Citrix Web Interface.
    i have a ASA 5505 that I am attempting to configure for WebVPN with passthrough into Web Interface .  The user authenticates into WebVPN OK and gets the option to click on the Citrix Link (which is i add bookmark  citrix server http:// 172.30.40.5.) i enter the citrix and then for example  i want to open to outlook it can not open. (when i want to open some application no application is open)).there is no alarm at asa. how i solve this issue?
    thanks.

    Teymur,
    Can you confim that after disabling the ssl/tls on the Citrix server (secure connectivity) that you are getting exactly the same error.  It is possible that it is generating a different error.
    The bug where we have see the existing error was CSCtf06303 but that has been fixed in 8.4.1.  Can you confirm the exact version of code you are running on the ASA.
    If you have confirmed the above two notes it may be adventageous to open a TAC case as we may need to do some live additional troubleshooting.
    Thanks
    -Jay

  • Distortion in Save For Web interface

    I am still having problems with my Save For Web interface. Attached is a screen where you can see that with just the Optimized view showing (in this case 72%), the picture looks as expected. But if I go to 2-up or 4-up views, the 2nd image (which was the 72% Optimized) is now all pixelated as if it were a GIF.

    OMG!  How many years have I been using this program and I have never noticed this until now?!?
    Sorry for the brain fart and thanks for pointing that out!!! 
    I am really having a good laugh at myself about this one!
    Jules

  • What's the best out-of-the-box web interface for a SQL DB?

    I'm developing a Java web application that will be backed by an Oracle database. Users would like a simple web interface that allows them to accomplish what they could with SQL queries without knowing SQL. The basic operations would be:
    * displaying a database table in a table format
    * downloading the table as a text or Excel file
    * customizing the columns in a table display
    * displaying a query result set in a table format
    * constructing a query using drop-down menus
    I'd probably want to program in a simplified UI for a few common queries.
    This really looks like functionality someone should have invented before me. Question: what is the right tool for me to be using? I'm surprised I haven't found something by searching.
    It looks like I could just directly write JSP, but I think something else might be simpler. I think related functionality exists in Spring, but I didn't find exactly what I'm looking for, and Spring brings a lot of other stuff also. Nothing in my application is more complicated than this, so I'd be happy to keep things simple.
    How would you write this?
    Edited by: 1010007 on Jun 5, 2013 7:22 AM

    Welcome to the forum!
    >
    I'm developing a Java web application that will be backed by an Oracle database. Users would like a simple web interface that allows them to accomplish what they could with SQL queries without knowing SQL. The basic operations would be:
    * displaying a database table in a table format
    * downloading the table as a text or Excel file
    * customizing the columns in a table display
    * displaying a query result set in a table format
    * constructing a query using drop-down menus
    I'd probably want to program in a simplified UI for a few common queries.
    This really looks like functionality someone should have invented before me. Question: what is the right tool for me to be using? I'm surprised I haven't found something by searching.
    It looks like I could just directly write JSP, but I think something else might be simpler. I think related functionality exists in Spring, but I didn't find exactly what I'm looking for, and Spring brings a lot of other stuff also. Nothing in my application is more complicated than this, so I'd be happy to keep things simple.
    How would you write this?
    >
    I wouldn't write it. I would just use Oracle's FREE Apex application which does all of that and more and is fully supported even on Oracle's FREE Express edition data database.
    http://www.oracle.com/technetwork/developer-tools/apex/overview/index.html
    >
    About Application Express
    Oracle Application Express (Oracle APEX), formerly called HTML DB, is a fully supported "no-cost" option of the Oracle Database. Oracle Application Express is certified against all editions of the Oracle Database 10.2.0.3 and above, including Oracle Database 10g Express Edition (Oracle XE).
    Oracle Application Express installs as part of the seed database installation with Oracle Database 11g.
    >
    The feature page (http://apex.oracle.com/pls/otn/f?p=4600:6:0) describes some of the major features of Apex
    >
    Browser Based
    Using only a Web browser and limited programming experience you can develop data centric applications in minutes. Browser-based development enables you to develop applications on most computers using only a modern Web browser.
    Rapid Application Development (RAD)
    Use simple wizards and declarative programming to create powerful reporting and data entry applications. You can create applications from spreadsheet uploads, or on existing database tables and views. Oracle Application Express includes SQL Workshop to create and manage the database objects that support your application.
    Application Express Components
    Application Builder - Database Applications
    Application developers use wizards to declaratively assemble applications organized in pages. Page content is organized into regions. Regions can contain text, custom PL/SQL, reports, charts, maps, calendars, web service references or forms. Forms are made up of fields (called items) which can be selected from the multitude of built-in types (such as text fields, text areas, radio groups, select lists, check boxes, date pickers, and popup list of values) or a developer can create their own types using plug-in support. Table update functionality is built-in and PL/SQL can be used to process data. Session state (or application context) is transparently managed and the user interface presentation is separated from the application logic so that the look and feel of an application can be changed simply by selected a different theme.
    Application Builder - Websheets
    Using Websheet Applications, end users can manage structured and unstructured data without developer assistance. Page sections contain unstructured data and are edited using a WYSIWYG editor. Reports provide access to database data by writing SQL. Data Grids can manage structured data without writing SQL. Adding columns, renaming column, and validations are defined using runtime dialogs. Each page and row of data grid data can be annotated with files, tags, notes, and links. Pages can contain sections as well as reports and data grids and all can be linked together providing navigation. All information is searchable and completely controlled by the end-user.
    SQL Workshop
    The SQL Workshop provides tools that enable you to view and manage database objects. Object Browser enables you to use a tree control to view object properties and create new objects. The SQL Command tool enables you to enter ad-hoc SQL. Query Builder enables you to create join queries using drag and drop. SQL Scripts enables you to store and run scripts. The Data Workshop enables you to load and unload text, DML, and spreadsheet data.
    RESTful Services
    RESTful Services allow for the declarative specification of RESTful services mapped to SQL and PL/SQL.
    Team Development
    Team Development helps manage the life-cycle of an application's development. It provides tracking and management of application features, to do entries, bugs, and end user feedback. Team Development is tightly integrated with the Oracle Application Express Application Builder. For example, edit page lists open feedback, bugs, and to do's.
    Administration
    Each Oracle Application Express workspace is a separate application development environment that is fully insulated from other workspaces. The administration component provides workspace management, including services (available schemas, space requests, and preferences), users (both developers and end-users), and workspace activity (page views, login attempts, and developer activity). Access is limited to Oracle Application Express developers who have workspace administration privileges.

  • BPS Web Interface don't show multiple documents for each cell

    Hi gurus,
    I have an issue... we are trying use text documents from BPS on the WEB interface. Everything works fine, I can input text documents on each cell on the web, and from Query as well.
    I saved several other documents from the query for the very same cell, and I can see these other documents from BPS itself or from the Query by clicking on the title... but on BPS WEB interface, it shows only the last text document saved.
    Is there anything wrong on the configuration, or is it possible for the WEB interface to show the titles so that the user can choose which document he wants to open?
    Thanks in advance,
    Chen

    Hi Luke,
    did you check whether the document attributes are generated for your Characteristics?
    AWB -> Documents -> Administration -> Generated Properties
    There is also a SAP Note 431126, which you might want to consult.
    Regards,
    Eric

  • Using default web interface for users

    I wish to use the default web interface for my users, I do not have the time to develop a custom app. I wish to get rid of the group and and mount point folders.
    Please Help,
    Jeff

    CM SDK 9.0.4 (released very shortly) includes the "Web Starter Application". This is a J2EE Web Application with full MVC architecture and completely open source!
    You may be able to obtain this application sooner from Oracle Consulting - it will work on the current CM SDK 9.0.3.
    JSP and Tag Libraries make up the UI. The controller framework is similar to Jakarta Struts. It offers localization support, ADA compliance etc.
    You can easily develop the application from JDeveloper and deploy to 9iAS.
    Matt.

  • WEB Interface for Visual Admin

    Hi,
    I'm told there is a web interface for the visial admin tool which can be launched from the examples section of the j2ee home page.
    In order to do this you must first deploy the tool.
    I've search the net and marketplace for the tool to download and am unable to find it.
    Has anyone else come across this before??
    Thanks
    Jim
    Message was edited by: Jim OShea

    Hi Jim,
    Are you looking for the Netweaver Administrator?
    Links:
    http://service.sap.com/nwa ( you will need a SAP Service Marketplace user ID for this)
    Introducing SAP NetWeaver Administrator -NWA
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/fc03a2a2-0a01-0010-b497-87518550e132
    Blog : SAP Developer Network Blog: XI: NetWeaver Administrator - first look - Logs & Traces (by Michal Krawczyk)
    /people/michal.krawczyk2/blog/2005/05/27/xi-netweaver-administrator--first-look--logs-traces
    Cheers
    Manish

Maybe you are looking for

  • I copied library to a new hard drive, now iphoto won't recognize files.

    I am new to iPhoto, so be gentle. My daughter uses it a lot, and now I seem to have messed up her library. We are using iPhoto 4.0.3. OS 10.4.11 I installed a new hard drive. I copied the iTunes and iPhoto libraries to the new larger hard drive. I co

  • Black Flashes in Premiere and on Final DVD

    I was not too concerned about the situation in the Source Monitor when about every 4 seconds I see a very fast, but obvious (nonetheless) Black Flash/Flicker on the screen. I thought it may be just a playback/RAM thing and that it would not go onto t

  • Installing and Uninstalling Forte 6, newbie questions..

    Hi, I really did not want to post these questions, but I have had no luck doing this and google hasn't been much help. First off, I have a botched install of Forte C 6U2 that needs to be uninstalled, it says to use the uninstall class in /var/sadm/pr

  • Acceptaing a variable with a quote in it

    Hi Guys, searched quite a bit but couldn't really find what I need. I have a sql report generated from a simple query where the user can type in what they need, I accept the parameter and generate the report, here is teh simple form for this question

  • Want to use sequence object of oracle when loading data in sql loader

    Hi, I want to use sequence when loading data in sqll loader, but the problem is i could not use sequence object of oracle to load the data by sql loader, i can use sequence of sql loader. I want to use sequence object because in later entries this se