-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is the last of the thread about a possible security breach at www.cvshome.org. The current conclusion is that there was and now is no security breach.  The odd behavior os tagged as some interaction between the server and particular browsers and mime type handling.  The final message is repeated below for your information. Alan - -------- Original Message -------- Subject: RE: Security Breach Alert - CVS Home File Download Area Compromised Date: Fri, 28 Jan 2005 15:20:24 -0800 From: Conrad T. Pino To: Info CVS , , Bug CVS CC: Kenneth Schwartzman ,   Philippe Turpault , Brian Noble Hi All, I just got off the phone with Kenneth Schwartzman of Collab Net. Kenneth reports the IT Engineering team investigated my report and found no evidence to support a security breach. The unexpected download behaviors I reported previously are now believed to be a consequence of MIME type information supplied by Apache 2.0 being acted upon differently by various browsers. Collab Net IT Engineering, Mark Baushke, Larry Jones and I all support this hypothesis. Collab Net IT Engineering understands the desirability of having a download content authentication method in place and will focus attention on this issue after completing more pressing issues. I'm closing this topic thread and will continue the issue as "Binary File Download Authentication" on the "Bug-CVS" list. I'm sorry for any inconvenience this false alarm may have caused but a prior recent successful breach made it seem prudent to raise an alarm even though only incomplete information was available. Best regards, Conrad T. Pino _______________________________________________ Info-cvs mailing list Info-cvs@gnu.org http://lists.gnu.org/mailman/listinfo/info-cvs -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFB+wW90VxxIfjPXe4RAiOEAJ9Qe94BjH7B7d4q8ZeBUt0n1ioptgCfQJD2 40tB++burltRJPLgLuGengQ= =bfnJ -----END PGP SIGNATURE----- --------------------------------------------------- PLUG-discuss mailing list - PLUG-discuss@lists.plug.phoenix.az.us To subscribe, unsubscribe, or to change you mail settings: http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss