[39640] in bugtraq

home help back first fref pref prev next nref lref last post

Re: blogtorrent remote/local user password disclosure

daemon@ATHENA.MIT.EDU (trashtrash@free.fr)
Thu Jul 14 17:37:59 2005

Date: 14 Jul 2005 05:55:54 -0000
Message-ID: <20050714055554.25479.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: trashtrash@free.fr
To: bugtraq@securityfocus.com

The proposed fix does not work.
How about placing a .htaccess with deny from all in the data and torrents directories ?

I'm not sure that there is a vulnerability. My version of blogtorrent (<0.92) has automatically created the .htaccess...

home help back first fref pref prev next nref lref last post