Re: Follow-up (was: no code? How can they do this?)
by "Mike Taylor" <lonewolf(at)one.net>
|
| Date: |
Tue, 20 May 2003 21:56:42 -0400 |
| To: |
<hwg-techniques(at)hwg.org> |
| References: |
michael speakeasy |
| |
todo: View
Thread,
Original
|
|
----- Original Message -----
From: "Jeff Nelson" <nelson_j(at)speakeasy.net>
> To those who thought it appropriate to post the exploit to a public list:
>
> This benefits you how, exactly? Show your technical expertise? (LOL!) If
> this was *your* site, what would you want someone who discovered a
> vulnerability to do? Post it in a public forum? I thought not.
I don't think anyone here intentionally thought to reveal an exploit on this
list. Mike Kear had originally asked how the author had posted a website
without using HTML code and I replied that it was done with JavaScript. A
few others followed up with links to the original scripts he'd used. It was
only later discovered --to our collective alarm-- that the author had placed
usernames and passwords in his source code. When we all realized he had
done this, nearly everyone expressed concern for the author and did what
they could to notify him of what they feared was an egregious security
error.
Fortunately, according to the author and Mike Kear, it was not an exploit at
all; his login system had never been intended as a means of secure
authentication.
HWG hwg-techniques mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.