[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] userList.php possible exploit



If it's only 6 lines of code - do you mind posting it to the list?

Bill

----- Original Message ----- 
From: "Anders" <andersb@xxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Sent: Tuesday, May 06, 2003 3:36 AM
Subject: Re: [cobalt-users] userList.php possible exploit


> Tom Honec wrote:
> 
> > I did not find this on the Sun Forums, I know they just
> > started using new ones, could it have been removed?
> 
> That would have been on the old buggy one... (December)
> 
> Either it looped itself out, or it got cleaned out
> after months of inactivity? It was noted by the admin
> Tony/Sun Microsystems, and as far as I know also reported
> to security-alert@xxxxxxx (it was not me reporting it)
> 
> I haven't seen an official response yet, though.
> Solution (security patch) is around 6 lines of code.
> I'll see what I can do, about us releasing a package?
> 
> --anders
> BlackSun Inc.
> http://www.blacksun.ca
> 
> _____________________________________
> cobalt-users mailing list
> cobalt-users@xxxxxxxxxxxxxxx
> To subscribe/unsubscribe, or to SEARCH THE ARCHIVES, go to:
> http://list.cobalt.com/mailman/listinfo/cobalt-users
>