Snort mailing list archives

Re: [Ntsug-users] Base 1.2 Vuln


From: Johnny Hernandez <johnny.hernandez () gmail com>
Date: Fri, 28 Oct 2005 09:22:40 -0500

Most of us that are within this network know it. I would believe that to be
Patrick's point. In my opinion, if you are running BASE and didn't know
this, you didn't do enough research prior to safely do so.

On 10/28/05, Justin Heath <justin.heath () gmail com> wrote:

With the way BASE is constantly plugged on this list it's a good idea to
point this out. Im sure there are people that weren't aware of this issue
that are running BASE. Just because you or someone else is aware of an issue
whether its "been brought up many times before" or not doesn't change
anything.

On 10/28/05, Patrick Harper <patrick () internetsecurityguru com> wrote:

This has been a known issue for a while. To quote Kevin (the lead
developer
of base)

This issue has been brought up many times before, not by this guy) and
is
CLEARLY documented in the README file since ACID was created. To fix
this
issue we need to completely rewrite the application and we are doing
this
for 2.x. Currently we are looking for a database expert to help with the
application. Do you know anyone?<g>)


-----Original Message-----
From: ntsug-users-bounces () ntsug org [mailto:
ntsug-users-bounces () ntsug org]
On Behalf Of Justin Heath
Sent: Friday, October 28, 2005 8:30 AM
To: Snort; General snort discussions
Subject: [Ntsug-users] Base 1.2 Vuln

I haven't seen any mention of this on the list, so I thought I would
pass it
along.

Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection
Vulnerability
http://www.securityfocus.com/bid/15199/info



_______________________________________________
Ntsug-users mailing list
Ntsug-users () ntsug org
http://www.ntsug.org/mailman/listinfo/ntsug-users



_______________________________________________
Ntsug-users mailing list
Ntsug-users () ntsug org
http://www.ntsug.org/mailman/listinfo/ntsug-users





--
Johnny Hernandez
214-850-1781

Current thread: