Full Disclosure mailing list archives
Vulnerability fixed in E-gold
From: 3APA3A <3APA3A () security nnov ru>
Date: Thu, 16 Mar 2006 01:17:49 +0300
Hello full-disclosure, bugtraq Netsling (shurik.f_(at)_gmail.com) reported vulnerability in E-gold. Vulnerability was reported and fixed in E-gold partner payment script. It was possible to transfer money from E-gold account without knowledge of AccounID/PassPhrase if user is logged on. Vulnerability details can be found at http://bhunter.awardspace.com/vuln-en.html The most interesting thing here is E-gold reaction: 1. Vendor fixed vulnerability within 24 hours. 2. Vendor decided to reward researcher without any request from his side. 3. Vendor gave permission to publish vulnerability information. Just ideal. I hope Microsoft to read this. Vulnerability was found and reported to E-gold by nestling, Web software developer from Russia. Please contact him directly, if you have any questions, because I was only asked to translate and publish this information. -- /3APA3A http://www.security.nnov.ru/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Vulnerability fixed in E-gold 3APA3A (Mar 15)
- Re: Vulnerability fixed in E-gold Georgi Guninski (Mar 16)
- Re[2]: Vulnerability fixed in E-gold 3APA3A (Mar 16)
- Re: Vulnerability fixed in E-gold Georgi Guninski (Mar 16)