--- /dev/null
+./commons-logging-api-1.1.1.jar
+./SizeOf.jar
+./commons-logging-1.1.1.jar
+./commons-logging-adapters-1.1.1.jar
+./log4j-1.2.16.jar
+./org.eclipse.osgi_3.8.0.v20120529-1548.jar
+./commons-compress-1.8.1.jar
+./commons-io-2.4.jar
+./ant-junit.jar
+./commons-logging-1.1.1-sources.jar
+./commons-logging-tests.jar
+./commons-logging-1.1.1-javadoc.jar
+./junit-4.5.jar
+./commons-lang3-3.5.jar
log4j.appender.TTY=org.apache.log4j.ConsoleAppender\r
log4j.appender.TTY.Threshold=DEBUG\r
log4j.appender.TTY.layout=org.apache.log4j.PatternLayout\r
-log4j.appender.TTY.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss.SSS} %-5p [%-28c{2}] - %m%n\r
+log4j.appender.TTY.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss.SSS} %-5p [%-28c{2}] - %m{nolookups}%n\r
+\r
+#NOTE: vulnerability with bare percent m style: https://news.ycombinator.com/item?id=29507263\r
\r
# LOGFILE is set to be a RollingFileAppender using a PatternLayout.\r
log4j.appender.LOGFILE=org.apache.log4j.RollingFileAppender\r
log4j.appender.LOGFILE.MaxBackupIndex=10\r
log4j.appender.LOGFILE.Threshold=DEBUG\r
log4j.appender.LOGFILE.layout=org.apache.log4j.PatternLayout\r
-log4j.appender.LOGFILE.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss.SSS} %-5p [%-28c{2}] - %m%n\r
+log4j.appender.LOGFILE.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss.SSS} %-5p [%-28c{2}] - %m{nolookups}%n\r
\r