Re: [PHP-DEV] Should I report this bug/exploit?

2005-04-04 Thread Derick Rethans
On Mon, 4 Apr 2005, Mark Krenz wrote: Is that a publically accessable mailing list or does it just go to a few people? Only a few people. Derick -- Derick Rethans http://derickrethans.nl | http://ez.no | http://xdebug.org -- PHP Internals - PHP Runtime Development Mailing List To

Re: [PHP-DEV] Should I report this bug/exploit?

2005-04-04 Thread Peter Brodersen
On Mon, 4 Apr 2005 09:13:04 +0200 (CEST), in php.internals [EMAIL PROTECTED] (Derick Rethans) wrote: Is that a publically accessable mailing list or does it just go to a few people? Only a few people. .. but don't expect any kind of feedback :-) (yeah, I know - I'm still yackin' about the

[PHP-DEV] Should I report this bug/exploit?

2005-04-03 Thread Mark Krenz
Hi, I've been using PHP for a long time and have recently found a couple of major bugs that would allow pretty much any user on a shared web hosting server to read other user's files. The conditions for this exploit are quite common. Also, from what I can tell, this exploit would not be

Re: [PHP-DEV] Should I report this bug/exploit?

2005-04-03 Thread Mark Krenz
Is that a publically accessable mailing list or does it just go to a few people? On Mon, Apr 04, 2005 at 04:35:59AM GMT, Rasmus Lerdorf [EMAIL PROTECTED] said the following: Such issues should be directed to [EMAIL PROTECTED] Mark Krenz wrote: Hi, I've been using PHP for a long time

Re: [PHP-DEV] Should I report this bug/exploit?

2005-04-03 Thread Wez Furlong
Please send details to [EMAIL PROTECTED] for further analysis. --Wez. On Apr 3, 2005 11:32 PM, Mark Krenz [EMAIL PROTECTED] wrote: Hi, I've been using PHP for a long time and have recently found a couple of major bugs that would allow pretty much any user on a shared web hosting server

Re: [PHP-DEV] Should I report this bug/exploit?

2005-04-03 Thread Rasmus Lerdorf
Such issues should be directed to [EMAIL PROTECTED] Mark Krenz wrote: Hi, I've been using PHP for a long time and have recently found a couple of major bugs that would allow pretty much any user on a shared web hosting server to read other user's files. The conditions for this exploit are