Re: [Full-disclosure] Drupal Help Injection Module XSS Vulnerability

2010-02-27 Thread Mori Sugimoto
Correction: Drupal Security Team _only_ deals with vulnerability reports that are related to major releases or release candidates. Mori Sugimoto Drupal Security Team On 27/02/2010 23:49, Mori Sugimoto wrote: > This module is still in alpha and not considered suitable for any > production enviro

Re: [Full-disclosure] Drupal Help Injection Module XSS Vulnerability

2010-02-27 Thread Mori Sugimoto
This module is still in alpha and not considered suitable for any production environment. Drupal Security Team does not deal with vulnerability reports that are related to major releases or release candidates. Instead we encourage reporters to contact the module maintainers and fix any issue in the

[Full-disclosure] Yahoo! UK and US Hiring Security and Risk management experts

2010-02-27 Thread Henri Torgemane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://careers.yahoo.com/ Looking for a dream job? Yahoo! is hiring security consultants worldwide 25-35 to help join our new Cyber Security Task Force. We are working with the government to provide a security service for our web and messenger plat

[Full-disclosure] Month of PHP Security 2010 - CALL FOR PAPERS

2010-02-27 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Month of PHP Security 2010 - CALL FOR PAPERS - Three years ago, in March 2007, the Hardened-PHP project had organized the Month of PHP Bugs. During one month more than 40 vulnerabilities in the PHP interpre