Full Disclosure mailing list archives
Re: Fun with Foundstone
From: "Dave Korn" <davek_throwaway () hotmail com>
Date: Tue, 14 Feb 2006 19:49:10 -0000
orangeofficer () hushmail com wrote:
Things for a security company not to do in a webapp: 1. Do not auto-populate form fields on the page with customer names. 2. If you ignore rule number 1, don't use a simple, predictable id for said auto-population. https://download.foundstone.com/?o=^2155
LOL, blocked already!
Rinse, increment, and repeat for a list of Foundstone customers...or at least a list of companies they've let download software.
... or at least a list of a million-and-one variants on "M. Mouse" and "Noah Body" ... ... nearly _all_ of whom appear to live in Beverley Hills. cheers, DaveK -- Can't think of a witty .sigline today.... _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Fun with Foundstone orangeofficer (Feb 14)
- Re: Fun with Foundstone Dave Korn (Feb 14)
- Re: Re: Fun with Foundstone ad () heapoverflow com (Feb 14)
- RE: Re: Fun with Foundstone Debasis Mohanty (Feb 14)
- Re: Re: Fun with Foundstone Dave Korn (Feb 15)
- RE: Re: Re: Fun with Foundstone Debasis Mohanty (Feb 15)
- Re: Re: Fun with Foundstone ad () heapoverflow com (Feb 14)
- Re: Re: Fun with Foundstone Dave Korn (Feb 15)
- Re: Fun with Foundstone Dave Korn (Feb 14)
- Re: Fun with Foundstone pagvac (Feb 16)