Activity
From 01/25/2016 to 02/23/2016
02/19/2016
- 09:16 AM Support #2998 (New): consider whether we should implement a separate security context for init/te...
02/11/2016
- 09:59 AM Bug #2994 (New): use static code analysis to scan p2j source for security vulnerabilities (Java, ...
- 09:57 AM Support #2993 (New): penetration testing: non-priviledged local user scenario
- 09:55 AM Support #2992 (New): penetration testing: remote access scenario
- 09:50 AM Support #2991: ensure that all XML parsing is done securely
- A useful quote from one of the above articles:
"Java applications using XML libraries are particularly vulnerable ... - 09:48 AM Support #2991: ensure that all XML parsing is done securely
- https://blog.detectify.com/2014/04/11/how-we-got-read-access-on-googles-production-servers/
https://www.owasp.org/in... - 09:47 AM Support #2991 (New): ensure that all XML parsing is done securely
02/04/2016
- 10:56 AM Bug #2981: replace SecurityManager.checkCaller() usage with a more performant approach
- We have long since implemented @SecurityManager.checkCaller()@/@SecurityManager.checkCallerAbort()@ as an approach to...
- 10:37 AM Bug #2981 (New): replace SecurityManager.checkCaller() usage with a more performant approach
02/03/2016
- 07:50 AM Bug #2693: terminating the server is broken (using ServerDriver -k)
- Just moving a reminder out of my email and into here:
Greg Shah wrote (in an email):
> The key is that the Server...
01/29/2016
- 12:00 PM Feature #2973: improve ContextLocal performance
- @ContextLocal@ is used very heavily throughout the runtime. Its @get@ method is hit constantly across various subsyst...
- 11:36 AM Feature #2973 (Closed): improve ContextLocal performance
Also available in: Atom