Full Disclosure mailing list archives
Re: seriously?
From: Michael Lenz <shadow.stalker () gmx de>
Date: Tue, 05 Apr 2011 12:19:22 +0200
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 It's rather stupid to make logfiles world-readable and -accessible, but .... should *we* care? Drop them a mail and tell them (how) to fix it. Yours, Michael On 05.04.2011 02:43, Ian French wrote:
hello all. came across this example of poor security. what do you think? http://www.sidneysdeptstore.com/lib/shared_components/WS_FTP.LOG _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk2a7KoACgkQ12k6J+72BxjZuQCfcrTWSCUKIN8PawyCD1sfe/gd T5UAn0oZ+AZdxhUcNiug/uOcrJXlaQi6 =zHkL -----END PGP SIGNATURE-----
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- seriously? Ian French (Apr 05)
- Re: seriously? Benji (Apr 05)
- Re: seriously? Michael Lenz (Apr 05)
- Re: seriously? Albert Sunseri (Apr 06)
- <Possible follow-ups>
- Re: seriously? Juha-Matti Laurio (Apr 05)