[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <200312060242.hB62gXps000602@turing-police.cc.vt.edu>
From: Valdis.Kletnieks at vt.edu (Valdis.Kletnieks@...edu)
Subject: (no subject)
On Sat, 06 Dec 2003 11:00:35 +1300, Nick FitzGerald <nick@...us-l.demon.co.uk> said:
> Indeed -- this is a classic exploit of a classic case of several
> _really, really BAD_ design decisions.
Mea culpa. Ignore my previous posting.
I thought you were flaming the guys at visa.com, when most of the blame goes to
the crackheads who desighed the HTTP URI format and the crackheads at MS who
implemented it. ;)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20031205/44ac6011/attachment.bin
Powered by blists - more mailing lists