Re: [Full-disclosure] ashnews Cross-Site Scripting Vulnerability

2006-01-30 Thread George A. Theall
On Tue, Jan 31, 2006 at 12:50:05AM +, Dan B UK wrote: > Did you even look at the source code for this script. If you had then > you would see that in the case of register_global's being turned on > there is a bigger issue to worry about; Remote/Local File Inclusion - > Server side. Is this

Re: [Full-disclosure] ntpd stack evasion exploit

2006-01-10 Thread George A. Theall
On Wed, Jan 11, 2006 at 12:29:35PM +1100, Sean Crawford wrote: > And judging from the original email I would say the Federal Reserve Bank of > Minneapolis may well be full of said vulnerabilities. > > Just the fact a bank employee is posting on a public list asking for help is > insane, but this