lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 21 Jan 2013 13:34:56 +0100 (CET) From: Santiago Vila <sanvila@...x.es> To: full-disclosure@...ts.grok.org.uk Subject: no-ip.com interesting way to handle newsletter options Hello. The newsletter no-ip.com sends to his customers has an unsubscribe link like this: http://www.no-ip.com/unsubscribe.php?email=user@example.com which means everybody can change your subscription options, just by knowing the email address you used to register. Let's see if this email helps them to disable the non privacy-aware PHP script more quickly. Thanks. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/