Re: [Full-disclosure] Mambo Cookie Authentication Bypass Exploit

2008-06-11 Thread crunkd
My social skills are great when it comes to talking to rational, non-fame-seeking people. However when the XSS and not-a-real-bug fanboys start posting someone has to stand up. As for you... I am sure you were that kid at school who told on the others just so the teacher would like you because

Re: [Full-disclosure] Mambo Cookie Authentication Bypass Exploit

2008-06-10 Thread Brian Kim
On Tue, Jun 10, 2008 at 3:05 AM, <[EMAIL PROTECTED]> wrote: > So to perform this 'bypass' you need the password in the first > place? You absolute fucking morons, the security scene is not for > you. I hope someone stabs you over a food stamp. Faggots. Although I agree with you in that it looks l

Re: [Full-disclosure] Mambo Cookie Authentication Bypass Exploit

2008-06-10 Thread Garrett M. Groff
attacks are disallowed. G - - Original Message - From: <[EMAIL PROTECTED]> To: Cc: <[EMAIL PROTECTED]> Sent: Tuesday, June 10, 2008 3:05 AM Subject: Re: [Full-disclosure] Mambo Cookie Authentication Bypass Exploit > So to perform this 'bypass' you need the pass

Re: [Full-disclosure] Mambo Cookie Authentication Bypass Exploit

2008-06-10 Thread crunkd
So to perform this 'bypass' you need the password in the first place? You absolute fucking morons, the security scene is not for you. I hope someone stabs you over a food stamp. Faggots. Halabaluza Team Halabaluza Team halabaluza.team

[Full-disclosure] Mambo Cookie Authentication Bypass Exploit

2008-06-09 Thread Halabaluza Team Halabaluza Team
for mambo <= 4.5.5 and <= 4.6.2 maybe others GET http://[TARGET]/index.php Host: [TARGET] User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9b5) Gecko/2008050509 Firefox/3.0b5 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Keep-A