Subject: Developers of Sympa
List archive
- From: David Verdin <address@concealed>
- To: address@concealed
- Subject: Re: [sympa-developpers] Identity hijacking
- Date: Mon, 03 Jun 2013 16:08:42 +0200
It's intended as a
feature, for virtual hosting: you have the server listmasters and
the virtual host listmasters, who can see only the vhost they are
in charge of. As a server listmaster, you can have to endorse a vhost listmaster identity to verify what she sees. It might be a security issue if a vhot listmaster could endorse the server listmasters' identity. Regards, David Le 03/06/13 15:48, Marc Chantreux a
écrit :
hello everyone, as listmaster, i was able to hijack the identity of another one (i don't know exactly how). I see it as a security hole want would like to investigate but maybe it's a feature (an easter egg? ;)). can someone tell me ? regards --
A bug in Sympa? Quick! To the bug tracker!
|
Attachment:
smime.p7s
Description: Signature cryptographique S/MIME
-
[sympa-developpers] Identity hijacking,
Marc Chantreux, 06/03/2013
-
Re: [sympa-developpers] Identity hijacking,
David Verdin, 06/03/2013
- Re: [sympa-developpers] Identity hijacking, Marc Chantreux, 06/04/2013
-
Re: [sympa-developpers] Identity hijacking,
David Verdin, 06/03/2013
Archive powered by MHonArc 2.6.19+.