Menu

#4 Spychat vulnerable to spurious activity in #spychat.status

open
nobody
None
5
2005-09-01
2005-09-01
Anonymous
No

Nate, you cad, you didn't put anybody in the
#spychat.status access list.

Turns out, evildoers (e.g. LarryIsKewl) can connect to it
and send messages to Spychat users, and they can't
block it. In turn, the victims spam #spychat.

Didn't you ever learn in computer security not to trust any
input until it has been double- and triple-checked?

Discussion


Log in to post a comment.

MongoDB Logo MongoDB