RE: [Full-Disclosure] FIREFOX flaws: nested array sort()

2004-11-25 Thread RandallM
So, where do you all stand. Exploit for fame or for purpose? > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Berend-Jan Wever > Sent: 25 November 2004 01:05 > To: [EMAIL PROTECTED]; > [EMAIL PROTECTED]; [EMAIL PROTECTED] > Subject: [Full-Discl

Re: [Full-Disclosure] FIREFOX flaws: nested array sort()

2004-11-25 Thread Ron
Sounds like he does it "For fun". That's what I'd do. RandallM wrote: So, where do you all stand. Exploit for fame or for purpose? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Berend-Jan Wever Sent: 25 November 2004 01:05 To: [EMAIL PROTECTED]; [E

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-25 Thread Juan Carlos Navea
> So instead you unleash it upon kiddie and spammer world? That's lovely. > Next you will come by again and say: "I'm still hoping I get to see the > guy who wrote those MyDoom worms in court, he violated the GPL and > spread millions(?) of copies of my (modified) source)." > So, you release it l

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-25 Thread Heikki Toivonen
Berend-Jan Wever wrote: I'd have loved to CC mozilla about this, but I didn't have the time to do the crash course "how to write a bug report" and go through all that bugzilla crap. Well, Mozilla does have a well know security email alias for those who don't have the time to do a crash course on B

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-26 Thread Jose Nazario
On Thu, 25 Nov 2004, Heikki Toivonen wrote: > 3. Either login if you already have an account, or click "create new > account". Let's assume we need to create a new account... > 4. Type in a valid email address and click "Create Account" > 5. [mail] Read email that was sent to the address to get pa

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-27 Thread Heikki Toivonen
Jose Nazario wrote: On Thu, 25 Nov 2004, Heikki Toivonen wrote: 3. Either login if you already have an account, or click "create new account". Let's assume we need to create a new account... requiring someone to register to post a bug is harmful in the sense that you wind up turning off peopl ewho

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-29 Thread exon
Jose Nazario wrote: On Thu, 25 Nov 2004, Heikki Toivonen wrote: 3. Either login if you already have an account, or click "create new account". Let's assume we need to create a new account... 4. Type in a valid email address and click "Create Account" 5. [mail] Read email that was sent to the addre

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-29 Thread Esben Stien
Jose Nazario <[EMAIL PROTECTED]> writes: > requiring someone to register to post a bug is harmful in the sense that > you wind up turning off peopl ewho simply can't be bothered to fill out > that info Exactly. -- Esben Stien is [EMAIL PROTECTED] http://www.esben-stien.name irc://irc.esben-sti

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-29 Thread Daniel Veditz
Jose Nazario wrote: > benefits of forcing/encouraging registration include: > - garaunteed line of followup > - reduced spam quantities in bugzilla > - at leasta cutofof "i care enough to ..." Currently more than half of the bugs that do get filed end up wasting time rather than

RE: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Sta ck overflow exception

2004-11-25 Thread Randal, Phil
An email to [EMAIL PROTECTED] would have sufficed. That email address can be found at http://www.mozilla.org/security/bug-bounty.html Phil Phil Randal Network Engineer Herefordshire Council Hereford, UK > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] O