Bugtraq mailing list archives

Re: Sourceforge compromized?


From: Karl Schlitt <karl () dakota-st com>
Date: Fri, 2 Feb 2007 12:46:02 -0600 (CST)

On Fri, 2 Feb 2007, Tim wrote:

Could someone from sourceforge.net comment? What else is compromised on
the server?

Can just anyone post anything to any directory or are there specific
directories that can be hacked?

Is it just yapig.sourceforge.net?


If you look here:

  http://yapig.sourceforge.net/


You'll see the following list of vulns recently fixed in this image
gallery project:


Just looking at the source for the defaced page one can see
that other projects are involved.

        http://owl.sourceforge.net/uploads/owl-13.php

-- 
Karl Schlitt
karl () dakota-st com


Current thread: