Re: [PHP] Severe Security Issue

2008-04-01 Thread Eric Butera
On Tue, Apr 1, 2008 at 11:37 AM, Daniel Brown <[EMAIL PROTECTED]> wrote: > On Tue, Apr 1, 2008 at 11:35 AM, Eric Butera <[EMAIL PROTECTED]> > wrote: > > > > It's April 1st regardless if he said to ignore it or not. :( > > Eric, > >That was actually the line I expected very few to refute, b

Re: [PHP] Severe Security Issue

2008-04-01 Thread Stut
Daniel Brown wrote: Off-list. Hey, don't shoot me down just yet, Mr. Dallas. Gotta' make the n00bs sweat it out just a bit, y'know. ;-P Sorry mate, bit too quick on the trigger there. And less of the real name on the interweb please, I'm undercover! -Stut -- http://stut.net/ On

Re: [PHP] Severe Security Issue

2008-04-01 Thread Daniel Brown
On Tue, Apr 1, 2008 at 11:35 AM, Eric Butera <[EMAIL PROTECTED]> wrote: > > It's April 1st regardless if he said to ignore it or not. :( Eric, That was actually the line I expected very few to refute, but it's exactly why I worded it that way. ;-P -- Forensic Services, Senior Unix Eng

Re: [PHP] Severe Security Issue

2008-04-01 Thread Eric Butera
On Tue, Apr 1, 2008 at 11:14 AM, Stut <[EMAIL PROTECTED]> wrote: > Daniel Brown wrote: > > Hey, folks, ignore the coincidence of the date when reading this > email. > > > I'm thinking you're full of it... > > http://lxr.php.net/search?string=remote_bytecode_include > > Since it doesn't appear

Re: [PHP] Severe Security Issue

2008-04-01 Thread Daniel Brown
Damn you, Reply-All -- Forensic Services, Senior Unix Engineer 1+ (570-) 362-0283 -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

Re: [PHP] Severe Security Issue

2008-04-01 Thread Daniel Brown
Off-list. Hey, don't shoot me down just yet, Mr. Dallas. Gotta' make the n00bs sweat it out just a bit, y'know. ;-P On Tue, Apr 1, 2008 at 11:14 AM, Stut <[EMAIL PROTECTED]> wrote: > Daniel Brown wrote: > > Hey, folks, ignore the coincidence of the date when reading this email. >

Re: [PHP] Severe Security Issue

2008-04-01 Thread Stut
Daniel Brown wrote: Hey, folks, ignore the coincidence of the date when reading this email. I'm thinking you're full of it... http://lxr.php.net/search?string=remote_bytecode_include Since it doesn't appear in the PHP source code I'm guessing it won't have any effect. Nice try. -Stut

[PHP] Severe Security Issue

2008-04-01 Thread Daniel Brown
Hey, folks, ignore the coincidence of the date when reading this email. During the Scranton PHP Group's meeting last night, the topic was security - go through all of the PHP engine's source code and identify and find patches for possible security issues. In the process, we detected a hug