[sldev] MAJOR/CRITICAL exploit for webbrowsers and SL?

Lawson English lenglish5 at cox.net
Tue Sep 18 10:07:57 PDT 2007


Erik Anderson wrote:
> You know, if this is an actual exploit then this list may not be the 
> appropriate place to continue discussions, I'm sorry that I 
> contributed at this point.
>

The whole point of open source , vis a vis exploints is to get these 
things out  in the open AND FIXED asap. Or such ha always been the claim 
of the open source community (or so I thought).

Certainly, since it appeared on a public webpage, there's no hiding the 
vulnerability.


> On 9/18/07, * Dale Glass* <dale at daleglass.net 
> <mailto:dale at daleglass.net>> wrote:
>
>     On Tuesday 18 September 2007 18:18:21 Lawson English wrote:
>     > This is a "show stopper" if the article is correct.
>     > _______________________________________________
>     > Click here to unsubscribe or manage your list subscription:
>     > /index.html
>
>     SL should use CRAM-MD5 for login. Then the hashed password
>     couldn't be
>     reused.
>
>
>     _______________________________________________
>     Click here to unsubscribe or manage your list subscription:
>     /index.html
>     </index.html>
>
>
>



More information about the SLDev mailing list