Re: [Full-Disclosure] Yahoo! Store Security Advisory

2004-09-25 Thread xploitable
On Sat, 25 Sep 2004 22:11:27 +0100, xploitable [EMAIL PROTECTED] wrote: On Fri, 24 Sep 2004 00:44:05 -0400, Stuart Moore [EMAIL PROTECTED] wrote: Yahoo! Store Security Advisory Advisory: http://securitytracker.com/id?1011403 Date: September 23, 2004 Vendor:Yahoo!

[Full-Disclosure] Yahoo! Store Security Advisory

2004-09-25 Thread xploitable
On Sat, 25 Sep 2004 17:38:29 -0400, Stuart Moore [EMAIL PROTECTED] wrote: xploitable, Yeah, it did take us some effort to get in touch with them. And they did not want to say thanks for reporting it. Oh well. I think having such a basic flaw in a commerce system speaks loudly about the

Re: [Full-Disclosure] Yahoo! Store Security Advisory

2004-09-25 Thread Byron L. Sonne
They don't know how to have a human discussion about serious flaws you send them. They are so self centred They make me want to act like a script kiddie and be malicious to the Yahoo! network, but of course I know thats a irresponsible thing to do. This is precisely why I say 'fuck it' and believe

[Full-Disclosure] Yahoo! Store Security Advisory

2004-09-23 Thread Stuart Moore
Yahoo! Store Security Advisory Advisory: http://securitytracker.com/id?1011403 Date: September 23, 2004 Vendor:Yahoo! Product: Yahoo! Store Status:Fixed by the vendor; Coordinated release Credit:Ben Efros [EMAIL PROTECTED] http://www.citiprice.com/