lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 18 Oct 2006 10:16:02 +0200
From: "Knud Erik Højgaard" <kokanin@...il.com>
To: disfigure <disfigure@...il.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Comdev One Admin 4.1 Remote File Inclusion

> - requires register globals on
> - requires magic quotes off

Seriously, who gives a shit then? And who gives a rats ass about file
inclusion in a crappy php script run only by you, your sister and the
author? It's as useful as buffer overflows in non-suid binaries, akin
to releasing advisories stating
- requires user to download and execute binary
- requires blank administrator password
- requires chmod +s /bin/*

> ADVISORY & EXPLOIT (requires registration):
> http://w4ck1ng.com/board/showthread.php?t=1491

BLA BLA HOW TO FIND BUGS LIKE THIS (requires lack of dayjob, desire
for 'fame'): wget -m crappy-php-coders.com/stupid-scripts ;  egrep -r
'include\(\$|require\(\$' . |
bugtraq-mailer-including-selfpromotion-crap

--
lol @ security 'industry', it's like printing ones own monies!!"3

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ