Re: blogtorrent remote/local user password disclosure
trashtrash_at_free.fr
Date: 07/14/05
- Previous message: Michael Stone: "[SECURITY] [DSA 746-1] New packages fix remote command execution in phpgroupware"
- Maybe in reply to: Emanuele Gentili: "blogtorrent remote/local user password disclosure"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 14 Jul 2005 05:55:54 -0000 To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is) The proposed fix does not work.
How about placing a .htaccess with deny from all in the data and torrents directories ?
I'm not sure that there is a vulnerability. My version of blogtorrent (<0.92) has automatically created the .htaccess...
- Previous message: Michael Stone: "[SECURITY] [DSA 746-1] New packages fix remote command execution in phpgroupware"
- Maybe in reply to: Emanuele Gentili: "blogtorrent remote/local user password disclosure"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|