[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] userList.php possible exploit
- Subject: Re: [cobalt-users] userList.php possible exploit
- From: "Bill Gibbs" <bgibbs@xxxxxxxxxxxxx>
- Date: Tue May 6 04:18:04 2003
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
If it's only 6 lines of code - do you mind posting it to the list?
Bill
----- Original Message -----
From: "Anders" <andersb@xxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Sent: Tuesday, May 06, 2003 3:36 AM
Subject: Re: [cobalt-users] userList.php possible exploit
> Tom Honec wrote:
>
> > I did not find this on the Sun Forums, I know they just
> > started using new ones, could it have been removed?
>
> That would have been on the old buggy one... (December)
>
> Either it looped itself out, or it got cleaned out
> after months of inactivity? It was noted by the admin
> Tony/Sun Microsystems, and as far as I know also reported
> to security-alert@xxxxxxx (it was not me reporting it)
>
> I haven't seen an official response yet, though.
> Solution (security patch) is around 6 lines of code.
> I'll see what I can do, about us releasing a package?
>
> --anders
> BlackSun Inc.
> http://www.blacksun.ca
>
> _____________________________________
> cobalt-users mailing list
> cobalt-users@xxxxxxxxxxxxxxx
> To subscribe/unsubscribe, or to SEARCH THE ARCHIVES, go to:
> http://list.cobalt.com/mailman/listinfo/cobalt-users
>