[Full-disclosure] Re: Advisory 18/2005: PHP Cross Site Scripting (XSS) Vulnerability in phpinfo()

From: Stefan Esser (sesser_at_php.net)
Date: 10/31/05

  • Next message: h4cky0u: "[Full-disclosure] HYSA-2005-009 Elite Forum 1.0.0.0 XSS Vulnerability"
    Date: Mon, 31 Oct 2005 19:15:31 +0100
    To: Matthew Murphy <mattmurphy@kc.rr.com>
    
    

    Hello Matthew,

    > That's a hell of a turnaround for you, Esser. It's the first security
    > bug I've reported in your software that's actually been fixed. And it
    > only took you *THREE YEARS*. We're finally making some progress here.

    Mr. Murphy, I don't know what your problem is, but the bug you refer to
    and that is described in the bug tracker post is not the bug the
    advisory contains. Just because you reported some XSS vulnerability in
    phpinfo() does not mean that you can claim credit for every phpinfo()
    XSS vulnerability that exists. So please simply shut up and go cry
    elsewhere.

    > Next time, you could try giving me credit for my research as well.
    > Thanks.

    Yeah well... If you report the bug first you can get credit.

    Stefan Esser

    -- 
    --------------------------------------------------------------------------
     Stefan Esser                                               sesser@php.net
     Hardened-PHP Project                         http://www.hardened-php.net/
     GPG-Key                gpg --keyserver pgp.mit.edu --recv-key 0x15ABDA78
     Key fingerprint       7806 58C8 CFA8 CE4A 1C2C  57DD 4AE1 795E 15AB DA78
    --------------------------------------------------------------------------
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/
    

  • Next message: h4cky0u: "[Full-disclosure] HYSA-2005-009 Elite Forum 1.0.0.0 XSS Vulnerability"

    Relevant Pages

    • Re: [patch] scsi: revert "[SCSI] Get rid of scsi_cmnd->done"
      ... Noone knows how many thousand bug reports have never reached lkml ... filing or get back to terminate the report. ... But I would like kernel people to become less egocentric ... Send _one_ email to lkml and you'll get forever spam to this address. ...
      (Linux-Kernel)
    • Re: 2.6.25-rc8: FTP transfer errors
      ... Yes, Mark, we used to do things that way for every bug in the kernel. ... We should be very careful about git-bisect. ... the developers, because when they think they might have fixed it, ... But I know that a report is a report, and even if I have a ...
      (Linux-Kernel)
    • Re: [patch] scsi: revert "[SCSI] Get rid of scsi_cmnd->done"
      ... Noone knows how many thousand bug reports have never reached lkml ... filing or get back to terminate the report. ... But I would like kernel people to become less egocentric ... Send _one_ email to lkml and you'll get forever spam to this address. ...
      (Linux-Kernel)
    • Re: Linux 2.6.21
      ... The kernel Bugzilla currently contains 1600 open bugs. ... Adrian, why do you keep harping on this, and ignoring reality? ... I suspect some bug reports get ignored deliberately. ... engage some developers on a bug report. ...
      (Linux-Kernel)
    • Bugfix(59/8=APNIC), math jobs (was: JDEE/CGI/flashcards ...)
      ... bug report so I could fix the problem quickly. ... > Note that I said it "looks" incomplete and buggy, ... > high math skills. ...
      (comp.lang.lisp)

  • Quantcast