[Imc-tech] Patch EMERGENCY!

Zachary C. Miller zach at chambana.net
Mon Oct 25 14:24:49 CDT 2004


In the future please provide a little more context about what the
nature of the "hack" is. When I see that there is a security
vulnerablity in some software on my system and a whole lot of "AWOOGA
AWOOGA EMERGENCY EVERYBODY TO GET FROM STREEET", my inclination is to
assume that it is a remote root exploit and that I need to rush home
and pull my system off the net.

That this is only a cross-site-scripting vulnerability makes me much
less worried as any damage that could be done can be undone very
easily. Please don't send off mega-super-panic alarms like that unless
there really is a mega-super-panic situation, my heart can't take
that.

Thank you Arun for working on the patch!

Do we need to search our database for instances of this exploit having
been used?

In other news:
http://www.news-gazette.com/story.cfm?Number=16969

Sascha Meinrath wrote:
> On Mon, 25 Oct 2004, Ryan Kaldari wrote:
> 
> > http://www.dadaimc.org/support.php?section=xss
> 
> can someone get on this ASAP -- two more IMC sites were _just_ hacked 
> (arkansas and colorado) -- we _will_ get hacked if we don't implement this 
> change immediately.
> 
> --sascha
> 
> -- 
> Sascha Meinrath
> Project Manager & Pres.   *   Project Coordinator   *   Policy Analyst
> Acorn Worker Collective  ***  CU Wireless Network  ***  Free Press
> www.acorncollective.com   *   www.cuwireless.net    *   www.freepress.net
> 
> 
> _______________________________________________
> Imc-tech mailing list
> Imc-tech at urbana.indymedia.org
> http://lists.cu.groogroo.com/cgi-bin/listinfo/imc-tech
> 

-- 
Zachary C. Miller - @= - Vote for Greens for Champaign County Board!
  Zach Miller   - District 9 (Urbana)    - http://votezach.org
  Susan Rodgers - District 8 (Campus)    - http://votesusanrodgers.org
  Ken Urban     - District 7 (Champaign) - http:/kenurban.com
   (DISCLAIMER: Political endorsements in my .sig are mine and mine alone.)


More information about the Imc-tech mailing list