Full Disclosure mailing list archives

Re: LinkedIn_User Account Delete using Click jacking


From: Peter Dawson <slash.pd () gmail com>
Date: Fri, 7 Oct 2011 15:25:55 -0400

if I get it right this dude is supposed to be "

   - Senior Security Analyst at iViZ Techno Solutions Pvt.
Ltd.<http://www.linkedin.com/company/iviz-techno-solutions-pvt.-ltd.?trk=ppro_cprof>

Whatever happened  on protocol's for  responsible disclosure ?

On Fri, Oct 7, 2011 at 3:05 PM, xD 0x41 <secn3t () gmail com> wrote:

Screw you dude, attaching executable doc files , and then pushing out a few
*0days*
I wont be looking at *any* thing attached as a doc, thats just common
sense. nowdays, and there is abs NO need on this list for it, it is FD, your
meant to put it in the BODY of email, or atleast maybe next time, change the
type to linux 0day and attach .S file... ??
screw u and ur advisorys, fix them into proper order asin written as any
would be, and ill read it, but never ask a dood to open the attachment!




  On 7 October 2011 22:48, asish agarwalla <asishagarwalla () gmail com>wrote:

 Hi,

LinkedIn_User Account Delete using Click jacking.

This Vulnerability is accepted by LinkedIn they are in a process
to patched it but not yet patched.

Please find the document describing the vulnerability.

Regards
Asish

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: