lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <43665F43.5050303@php.net>
Date: Mon, 31 Oct 2005 19:15:31 +0100
From: Stefan Esser <sesser@....net>
To: Matthew Murphy <mattmurphy@...rr.com>
Cc: red@...sec.de, full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Re: Advisory 18/2005: PHP Cross Site Scripting
 (XSS)	Vulnerability in phpinfo()


Hello Matthew,

> That's a hell of a turnaround for you, Esser.  It's the first security
> bug I've reported in your software that's actually been fixed.  And it
> only took you *THREE YEARS*.  We're finally making some progress here.

Mr. Murphy, I don't know what your problem is, but the bug you refer to
and that is described in the bug tracker post is not the bug the
advisory contains. Just because you reported some XSS vulnerability in
phpinfo() does not mean that you can claim credit for every phpinfo()
XSS vulnerability that exists. So please simply shut up and go cry
elsewhere.

> Next time, you could try giving me credit for my research as well. 
> Thanks.

Yeah well... If you report the bug first you can get credit.

Stefan Esser

-- 
--------------------------------------------------------------------------
 Stefan Esser                                               sesser@....net
 Hardened-PHP Project                         http://www.hardened-php.net/

 GPG-Key                gpg --keyserver pgp.mit.edu --recv-key 0x15ABDA78
 Key fingerprint       7806 58C8 CFA8 CE4A 1C2C  57DD 4AE1 795E 15AB DA78
--------------------------------------------------------------------------

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ