discuss@mandoc.bsd.lv
 help / color / mirror / Atom feed
* man.cgi and gzip manuals: bug or feature
@ 2020-02-16 11:59 Stephen Gregoratto
  2020-02-16 12:43 ` Jan Stary
  2020-02-16 15:30 ` Ingo Schwarze
  0 siblings, 2 replies; 4+ messages in thread
From: Stephen Gregoratto @ 2020-02-16 11:59 UTC (permalink / raw)
  To: discuss

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain; charset=unknown-8bit, Size: 436 bytes --]

man.cgi doesn't handle serving gzipped manuals, with it dumping the raw
bytes onto the user's screen. You can view a simple test I made to
illustrate[1]. Not sure if this is a bug or some way of reducing attack
service ¯\_(ツ)_/¯.

[1] https://man.sgregoratto.me/gzip-test/man1/sh.1
    https://man.sgregoratto.me/gzip-test/man1/sh-plain.1
-- 
Stephen Gregoratto
--
 To unsubscribe send an email to discuss+unsubscribe@mandoc.bsd.lv

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2020-02-16 15:30 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-02-16 11:59 man.cgi and gzip manuals: bug or feature Stephen Gregoratto
2020-02-16 12:43 ` Jan Stary
2020-02-16 12:55   ` Stephen Gregoratto
2020-02-16 15:30 ` Ingo Schwarze

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).