Re: Richard Stallman...

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: L <L@...>
To: <rms@...>
Cc: misc <misc@...>
Date: Sunday, January 6, 2008 - 8:48 am

Richard Stallman wrote:

Can you tell the FSF web programmers to do more checking for HTML/SQL
injection vulnerabilities?
I have found a vulnerability with your FSF search engine.

http://z505.com/gng/fsf-gnu-site-easy-to-hack.htm

Your programmers should check POST/GET variables and in many cases only
allow alpha numeric characters in by default. Not through javascript but
at the server side during processing. Your search engine allows bad
characters in.. ones that can damage the site or cause malicious theft
of logins or other data through cross site scripting.. by embedding
forms/input boxes into the site that post to another domain.

In the framework I develop, this problem is secured by default...
The functions I use for getting a post/get variables, trim malicious
attempts.. while the programmer can choose to use the insecure non
default raw function if he really needs to:
http://z505.com/cgi-bin/powtils/docs/1.6/idx.cgi?file=getcgivar&unit=pwu...
http://z505.com/cgi-bin/powtils/docs/1.6/idx.cgi?file=getcgivar_s&unit=p...

I suggest your web programmers read up on how to secure web programs by
reading about what my GetCgiVar functions do, or by finding articles on
the net that explain how you have to filter/check each incoming POST/GET
request carefully each time.

I would have sent this privately to you, but many people will find this
security info useful and humorous. It is my duty to teach people about
web security, and only privately mailing you would mean thousands of
people that read this list would miss out on learning about HTML
injection. Plenty of large popular websites I visit are insecure in this
very manner.

Since this vulnerability is unfortunately exposed publicly.. fixing it
before too many people notice it would be good.

Regards,
L505

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Richard Stallman..., Mayuresh Kathe, (Fri Jan 4, 10:05 am)
Re: Richard Stallman... , Theo de Raadt, (Fri Jan 4, 1:08 pm)
Re: Richard Stallman..., Richard Stallman, (Sat Jan 5, 10:31 am)
Re: Richard Stallman..., Craig Skinner, (Mon Jan 7, 6:21 am)
Re: Richard Stallman..., johan beisser, (Sat Jan 5, 11:30 am)
Re: Richard Stallman..., Richard Stallman, (Sun Jan 6, 6:46 am)
Re: Richard Stallman..., Duncan Patton a Campbell, (Mon Jan 7, 6:32 am)
Re: Richard Stallman..., johan beisser, (Sun Jan 6, 2:42 pm)
Re: Richard Stallman..., Richard Stallman, (Mon Jan 7, 7:30 am)
Re: Richard Stallman..., Eric Furman, (Tue Jan 8, 3:48 pm)
Re: Richard Stallman..., Jan Stary, (Mon Jan 7, 11:46 am)
Re: Richard Stallman..., nicodache, (Mon Jan 7, 1:32 pm)
Re: Richard Stallman..., Steve Shockley, (Mon Jan 7, 6:41 pm)
Re: Richard Stallman..., knitti, (Tue Jan 8, 9:25 am)
Re: Richard Stallman..., Gregg Reynolds, (Tue Jan 8, 12:22 am)
Re: Richard Stallman..., Alexander Hall, (Tue Jan 8, 8:34 am)
Re: Richard Stallman..., Dusty, (Sun Jan 6, 9:10 am)
Re: Richard Stallman..., Marco Peereboom, (Sat Jan 5, 1:39 pm)
Re: Richard Stallman..., johan beisser, (Sat Jan 5, 2:53 pm)
Re: Richard Stallman..., Sunnz, (Sat Jan 5, 11:24 am)
Re: Richard Stallman..., Richard Stallman, (Sun Jan 6, 6:47 am)
Re: Richard Stallman..., L, (Sun Jan 6, 8:48 am)
Re: Richard Stallman..., Richard Stallman, (Mon Jan 7, 12:18 am)
Re: Richard Stallman..., Jacob Meuser, (Mon Jan 7, 9:07 am)
Re: Richard Stallman..., johan beisser, (Mon Jan 7, 1:02 am)
Re: Richard Stallman..., L, (Mon Jan 7, 3:43 am)
Re: Richard Stallman..., Richard Stallman, (Mon Jan 7, 1:15 pm)
Re: Richard Stallman..., L, (Mon Jan 7, 11:29 pm)
Re: Richard Stallman..., L, (Mon Jan 7, 11:46 pm)
Re: Richard Stallman..., Rico Secada, (Tue Jan 8, 2:07 pm)
Re: Richard Stallman..., Jacob Meuser, (Mon Jan 7, 8:24 pm)
Re: Richard Stallman..., L, (Mon Jan 7, 11:20 pm)
Re: Richard Stallman..., Andrés, (Sat Jan 5, 11:30 am)
Re: Richard Stallman..., Gilles Chehade, (Sat Jan 5, 10:51 am)
Re: Richard Stallman... , Maxim Bourmistrov, (Fri Jan 4, 5:32 pm)
Re: Richard Stallman..., Siju George, (Fri Jan 4, 2:09 pm)
Re: Richard Stallman..., chefren, (Fri Jan 4, 2:31 pm)
Puffy 'Wizard of OS' (Was: Re: Richard Stallman...), Ken Ismert, (Fri Jan 4, 5:54 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Fri Jan 4, 10:29 am)
Re: Richard Stallman..., Gilles Chehade, (Fri Jan 4, 7:49 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 7:53 am)
Re: Richard Stallman..., Gilles Chehade, (Sat Jan 5, 10:47 am)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 1:53 pm)
Re: Richard Stallman..., William Boshuck, (Sat Jan 5, 4:05 pm)
Re: Richard Stallman..., Eliah Kagan, (Sat Jan 5, 2:51 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 4:54 pm)
Re: Richard Stallman..., Eliah Kagan, (Sat Jan 5, 8:46 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 9:31 pm)
Re: Richard Stallman..., Gary Baluha, (Mon Jan 7, 11:10 am)
Re: Richard Stallman..., Gilles Chehade, (Sat Jan 5, 2:34 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 8:56 pm)
Re: Richard Stallman..., Gary Baluha, (Mon Jan 7, 11:04 am)
Re: Richard Stallman..., Gilles Chehade, (Sun Jan 6, 8:18 am)
Re: Richard Stallman..., johan beisser, (Sat Jan 5, 9:22 pm)
Re: Richard Stallman..., Marco Peereboom, (Sat Jan 5, 8:34 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 9:10 pm)
Re: Richard Stallman..., Ray Percival, (Sat Jan 5, 2:28 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 9:07 pm)
Re: Richard Stallman..., Alexander Terekhov, (Sat Jan 5, 2:52 pm)
Re: Richard Stallman..., L, (Sat Jan 5, 2:31 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 9:06 pm)
Re: Richard Stallman..., L, (Sat Jan 5, 9:18 pm)
Re: Richard Stallman..., Rui Miguel Silva Seabra, (Sat Jan 5, 9:34 pm)
Re: Richard Stallman..., L, (Sat Jan 5, 11:30 pm)
Re: Richard Stallman..., L, (Sun Jan 6, 12:28 am)
Re: Richard Stallman..., Lars Noodén, (Sun Jan 6, 12:17 am)
Re: Richard Stallman..., L, (Sun Jan 6, 12:41 am)
Re: Richard Stallman..., Koh Choon Lin, (Sun Jan 6, 4:58 am)
Re: Richard Stallman..., Eric Furman, (Tue Jan 8, 2:07 pm)