Full Disclosure mailing list archives
Re: Is OWASP vulnerable ??
From: jf <jf () danglingpointers net>
Date: Sun, 11 Mar 2007 12:21:05 +0000 (UTC)
Paul, if you find a way to get something to execute an eval() with data that you control, and all you can get out of that is an information disclosure, you *really* need to find a new line of work.
Valdis, its javascript, as in client side, if you want to eval() something on your machine, use notepad/vi. An undefined variable isn't going to get you *anywhere* without some other bug, i.e. XSS, which makes the undefined variable a moot point. *You* should consider a new line of work. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Is OWASP vulnerable ?? Scarlet Pimpernel (Mar 10)
- Re: Is OWASP vulnerable ?? jf (Mar 10)
- Re: Is OWASP vulnerable ?? Paul Schmehl (Mar 10)
- Re: Is OWASP vulnerable ?? Valdis . Kletnieks (Mar 10)
- Re: Is OWASP vulnerable ?? Paul Schmehl (Mar 10)
- Re: Is OWASP vulnerable ?? Valdis . Kletnieks (Mar 10)
- Re: Is OWASP vulnerable ?? Paul Schmehl (Mar 10)
- Re: Is OWASP vulnerable ?? jf (Mar 10)
- Re: Is OWASP vulnerable ?? czino2 (Mar 11)
- Re: Is OWASP vulnerable ?? Michael Silk (Mar 11)
- Re: Is OWASP vulnerable ?? Valdis . Kletnieks (Mar 10)
- Re: Is OWASP vulnerable ?? Scarlet Pimpernel (Mar 10)
- Re: Is OWASP vulnerable ?? jf (Mar 10)
- Re: Is OWASP vulnerable ?? czino2 (Mar 11)
- <Possible follow-ups>
- Re: Is OWASP vulnerable ?? Steven M. Christey (Mar 12)
