User Activity

  • Posted a comment on ticket #649 on PhpWiki

    It's not an online scanner, it's scanning offline on the filesystem. I can test that even without an installation. The only issue here is that I have a database with information of the form "app X had its last security vuln Y that was fixed in Z". It seems right now there is no fixed version, so that's what I'm reporting. I can update it once you make a new release. See here how the data looks: https://git.schokokeks.org/freewvs.git/blob/master/freewvsdb/wiki.json

  • Posted a comment on ticket #649 on PhpWiki

    I'm not running phpwiki myself, I'm developing a tool that scans for vulnerable web applications [1]. [1] https://source.schokokeks.org/freewvs/

  • Created ticket #472 on phpPgAdmin

    Cross Site Scripting vulnerability

  • Created ticket #649 on PhpWiki

    Security vulnerabilities described on exploit-db

  • Created ticket #125 on pam_mount module

    pam_mount uses deprecated openssl 1.1 features

  • Posted a comment on ticket #890 on Enigmail

    Can I ask what the fix is? Your comment indicates this is an underlying thunderbird issue and can't be fixed within Enigmail.

  • Modified a comment on ticket #2831 on SquirrelMail

    I created a patch that fixes all those issues and a few more. Appart from the ones you mentioned it is also possible to achieve XSS via the formaction attribute or via svg animations (animate to attribute). I'm now adding a lot more filtering, but I believe this doesn't break any common html mails, as other webmailers apply similar filtering. I'm completely removing inline SVG (gmail does the same, so I don't think anyone uses them). Some of the filtering is now redundant, but it may help kill further...

  • Posted a comment on ticket #2831 on SquirrelMail

    I created a patch that fixes all those issues and a few more. Appart from the ones you mentioned it is also possible to achieve XSS via the formaction attribute or via svg animations (animate to attribute). I'm now adding a lot more filtering, but I believe this doesn't break any common html mails, as other webmailers apply similar filtering. I'm completely removing inline SVG (gmail does the same, so I don't think anyone uses them). Some of the filtering is now redundant, but it may help kill further...

View All

Personal Data

Username:
ctulhu
Joined:
2001-08-25 08:16:34
Web Site:
  1. https://hboeck.de/

Projects

This is a list of open source software projects that Hanno Böck is associated with:

Personal Tools