Re: [Full-disclosure] Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability

2007-02-24 Thread Stefan Esser
Matthew Flaschen schrieb: Stefan Esser wrote: Microsoft just sent a nonsense mail to us, claiming that we had disclosed this already to the public and that they like getting advance notice. I mean, that's fair enough. I mean, nobody's personality should get in the way of

Re: [Full-disclosure] Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability

2007-02-24 Thread pdp (architect)
indeed On 2/23/07, Michal Zalewski [EMAIL PROTECTED] wrote: On Fri, 23 Feb 2007, Stefan Esser wrote: Proof of Concept: The Hardened-PHP Project is not going to release a proof of concept exploit for this vulnerability. ...because pretty much no exploit is needed. Scary. Good

Re: [Full-disclosure] Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability

2007-02-23 Thread Michal Zalewski
On Fri, 23 Feb 2007, Stefan Esser wrote: Proof of Concept: The Hardened-PHP Project is not going to release a proof of concept exploit for this vulnerability. ...because pretty much no exploit is needed. Scary. Good catch. /mz ___

Re: [Full-disclosure] Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability

2007-02-23 Thread Matthew Flaschen
Stefan Esser wrote: Microsoft just sent a nonsense mail to us, claiming that we had disclosed this already to the public and that they like getting advance notice. I mean, that's fair enough. I mean, nobody's personality should get in the way of fixing security vulnerabilities. Err,

[Full-disclosure] Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability

2007-02-23 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hardened-PHP Project www.hardened-php.net -= Security Advisory =- Advisory: Multiple Browsers Cross Domain Charset Inheritance Vulnerability Release Date: 2007/02/23 Last