[Date Prev] [Date Next] [Prev in Thread] [Next in Thread] [Date Index] [Thread Index]

Re: [RSSO] Problem with some bypass URLs



Hi Carl,

cannyou give me a clue regarsing a córeczka bypass?

RSSO on port 8090? Where do you have that from? Why does it matter? I would appreciate if you could elaborate is that BMC documentation is still on open source level.

Thank you
Thomas

On 8. Mar 2018, at 22:59, Carl Wilson <carlbwilson@gmail.com> wrote:

Hi,
Seems like the first part of your RSSO bypass is not correct. 
Usually RSSO is on port 8090, your URL shows 8080 for both RSSO and MT. 

Cheers 
Carl

On Thu, 8 Mar 2018, 21:56 Misi Mladoniczky, <miz@rrr.se> wrote:
Hi Thomas,

You should URL Encode the data part of your urls.

For example
http://our_domain:8080/arsys/forms/ourars/AR System Midtier Object List
http%3A%2F%2Four_domain%3A8080%2Farsys%2Fforms%2Fourars%2FAR%20System%20Midtier%20Object%20List

So the complete string would read:
http://our_domain:8080/rsso/start?bypass-auth=true&tenant=*&goto=http%3A%2F%2Four_domain%3A8080%2Farsys%2Fforms%2Fourars%2FAR%20System%20Midtier%20Object%20List

I used this site to do it now: https://meyerweb.com/eric/tools/dencoder/

Best Regards - Misi, RRR AB, http://www.rrr.se (ARSList MVP 2011)

Ask the Remedy Licensing Experts (Best R.O.I. Award at WWRUG10/11/12/13)
* RRR|License - Not enough Remedy licenses? Save money by optimizing.
* RRR|Log - Performance issues or elusive bugs? Analyze your Remedy logs
Find these products, and many free tools and utilities, at http://rrr.se





March 8, 2018 8:25 PM, "Thomas Miskiewicz" <tmiskiew@gmail.com> wrote:
Hi Listers,
URLs like:

http://our_domain:8080/rsso/start?bypass-auth=true&tenant=*&goto=http://our_domain:8080/arsys/forms/ourars/AR+System+Midtier+Object+List/Default+Admin+View/
http://our_domain:8080/rsso/start?bypass-auth=true&tenant=*&goto=http://our_domain:8080/arsys/forms/ourars/ABC%3AControlCenter/Default+Administrator+View/
give us HTTP 404.
It seems that the Tomcat / RSSO doesn’t like the blanks or colons in the goto part. Any idea how to fix this?
Thanks
Thomas
--
ARSList mailing list
ARSList@arslist.org
https://mailman.rrr.se/cgi/listinfo/arslist