Full Disclosure mailing list archives
Fun with Foundstone
From: <orangeofficer () hushmail com>
Date: Tue, 14 Feb 2006 11:35:14 -0600
Things for a security company not to do in a webapp: 1. Do not auto-populate form fields on the page with customer names. 2. If you ignore rule number 1, don't use a simple, predictable id for said auto-population. https://download.foundstone.com/?o=^2155 Rinse, increment, and repeat for a list of Foundstone customers...or at least a list of companies they've let download software. Now that's just plain sloppy. Concerned about your privacy? Instantly send FREE secure email, no account required http://www.hushmail.com/send?l=480 Get the best prices on SSL certificates from Hushmail https://www.hushssl.com?l=485 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Fun with Foundstone orangeofficer (Feb 14)
- Re: Fun with Foundstone Dave Korn (Feb 14)
- Re: Re: Fun with Foundstone ad () heapoverflow com (Feb 14)
- RE: Re: Fun with Foundstone Debasis Mohanty (Feb 14)
- Re: Re: Fun with Foundstone Dave Korn (Feb 15)
- RE: Re: Re: Fun with Foundstone Debasis Mohanty (Feb 15)
- Re: Re: Fun with Foundstone ad () heapoverflow com (Feb 14)
- Re: Re: Fun with Foundstone Dave Korn (Feb 15)
- Re: Fun with Foundstone Dave Korn (Feb 14)
- Re: Fun with Foundstone pagvac (Feb 16)