Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-18 Thread Jacqui Caren-home
On 15/02/2011 16:55, Michele Orru wrote: > 2011/2/14 MustLive: >> Hello Michele! >> >> Few days ago I saw your advisory about Drupal's captcha. It's interesting >> advisory, but I have one note concerning it - your research is very close to >> mine ;-) (it concerns similar holes which I found befor

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-15 Thread Eyeballing Weev
Some guys pay more for women with "extra hardware". What are you doing later? ;-) > What the hell :) > I'm a man mate. > > Michele is like Michael. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-15 Thread Michele Orru
On Tue, Feb 15, 2011 at 12:25 AM, Eyeballing Weev wrote: > > > On Mon, Feb 14, 2011 at 4:54 PM, MustLive > wrote: >> >> Hello Michele! >> >> Few days ago I saw your advisory about Drupal's captcha. It's interesting >> advisory, but I have one note concerning it - your research is very close >> to

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-15 Thread Michele Orru
2011/2/14 MustLive : > Hello Michele! > > Few days ago I saw your advisory about Drupal's captcha. It's interesting > advisory, but I have one note concerning it - your research is very close to > mine ;-) (it concerns similar holes which I found before you). I didn't found anything in FD or other

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-14 Thread Eyeballing Weev
On Mon, Feb 14, 2011 at 4:54 PM, MustLive wrote: > Hello Michele! > > Few days ago I saw your advisory about Drupal's captcha. It's interesting > advisory, but I have one note concerning it - your research is very close > to > mine ;-) (it concerns similar holes which I found before you). > Quit

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-14 Thread MustLive
Hello Michele! Few days ago I saw your advisory about Drupal's captcha. It's interesting advisory, but I have one note concerning it - your research is very close to mine ;-) (it concerns similar holes which I found before you). First, you are talking Drupal captcha and saying that Drupal <= 6.20