[prev in list] [next in list] [prev in thread] [next in thread] 

List:       tor-talk
Subject:    Re: [tor-talk] XSS on blog.torproject.org - 8 month old ticket?
From:       isis <isis () torproject ! org>
Date:       2014-08-19 22:22:37
Message-ID: 20140819222237.GX23636 () patternsinthevoid ! net
[Download RAW message or body]

[Attachment #2 (multipart/signed)]


Nusenu transcribed 1.3K bytes:
> By coincidence I stumbled on a 8 months old ticket reporting a XSS
> vulnerability on blog.torproject.org - and it is still vulnerable.
> This is not exactly inspiring confidence.
> 
> I reassigned the ticket to phobos. Lets hope that this change something.
> 
> 
> https://trac.torproject.org/projects/tor/ticket/10440
> 

The best way to see a change done is to do it yourself. Also see
https://trac.torproject.org/projects/tor/ticket/10022 which probably explains
why no one has fixed the XSS.

-- 
 ♥Ⓐ isis agora lovecruft
_________________________________________________________
GPG: 4096R/A3ADB67A2CDB8B35
Current Keys: https://blog.patternsinthevoid.net/isis.txt

["signature.asc" (application/pgp-signature)]

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic