Re: [Full-disclosure] Blogger bug?

2006-10-09 Thread Eric Chien
On 10/9/06, Peter Dawson <[EMAIL PROTECTED]> wrote:  Host Overflow Application eXception vulnerability is in the wild – any blog that supports RSS and MetaWeblogAPI can be h4x0red.   We don't have confirmed vectors yet for this incident The Host Overflow Application eXception thing appears to be a

Re: [Full-disclosure] Blogger bug?

2006-10-09 Thread Peter Dawson
Symantec is report the same flaw   http://www.symantec.com/enterprise/security_response/weblog/2006/10/host_overflow_application_exce.html   On 10/8/06, Peter Dawson <[EMAIL PROTECTED]> wrote:  Host Overflow Application eXception vulnerability is in the wild – any blog that supports RSS and MetaWe

Re: [Full-disclosure] Blogger bug?

2006-10-08 Thread Peter Dawson
 Host Overflow Application eXception vulnerability is in the wild – any blog that supports RSS and MetaWeblogAPI can be h4x0red.   We don't have confirmed vectors yet for this incident   On 10/8/06, Mike McMan <[EMAIL PROTECTED]> wrote: Looks like there was a bug in blogger that let someone make a

[Full-disclosure] Blogger bug?

2006-10-08 Thread Mike McMan
Looks like there was a bug in blogger that let someone make a fake post on the official Google blog. http://googleblog.blogspot.com/2006/10/about-that-fake-post.html http://www.techcrunch.com/2006/10/07/strange-things-afoot-at-the-google-blog/ Anyone have any details on the bug? ___