Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: Multiple Phorum XSS and Session Hijacking vulnerabilities

Re: Multiple Phorum XSS and Session Hijacking vulnerabilities

From: Scott Dewey <wr0ck.lists_at_gmail.com>
Date: Fri, 02 Sep 2005 13:00:48 -0400

Brian Moon wrote:
> First, all issues that will allow any of the issues here to happen have
> been fixed. With 5.0.18a, you can not use any method described below.
> We had the fixes done in less than 24 hours.
>
> Now, what a professional and responsible post. I normally don't reply
> to these emails, but this person has misrepresented the communications
> we had with him. It makes me not want to communicate with people that
> report security flaws. If I had known he would use my words out of
> context this way, I would have just released the new version and ignored
> his email.
>
> "Scott" clearly has another agenda here. That is to discredit
> applications and promote interests of his own. The mention of IPB
> specifically makes that clear.
>
> Brian Moon
> Phorum Dev Team
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

I commend you and your team on resolving the issues in a timely manner.

I do not believe I misrepresented any of the communications between us,
and I don't think I took anything out of context. I quoted what was said
is all.

If my "agenda" is to help you and your development team by not only
alerting you of the problem, but offering up possible solutions to
remedy the issues, then you're probably right. But to say that I'm
trying to discredit your application and promote interests of my own
(IPB is not an interest of mine) is wrong.

Perhaps we should take this off-list, there's no sense in debating it
here.. no sense in debating this at all even, nobody cares.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Sep 02 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]