Re: [Savannah-help-public] security bug and propose to join

2008-01-06 Thread Sylvain Beucler
> > There's plenty places to help at GNU. Do you have something precise in > > mind? > > > I'd like help about auditing webapps, I'm contributor in ubuntu GNU/Linux. > https://edge.launchpad.net/~emgent Hi, You may be interested in reviewing the Savane code. The Savannah branch is public can be

Re: [Savannah-help-public] security bug and propose to join

2008-01-05 Thread Sylvain Beucler
Hi, On Sat, Jan 05, 2008 at 12:17:32PM +0100, Emanuele Gentili wrote: > Hello people. > > I was found some security bug in savannah.gnu.org. > > http://savannah.gnu.org/cookbook/?func=detailitem&comingfrom=23&item_id=%22%3E%3Cscript%3Ealert(420)%3C/script%3E > https://savannah.gnu.org/account/lo

[Savannah-help-public] security bug and propose to join

2008-01-05 Thread Emanuele Gentili
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello people. I was found some security bug in savannah.gnu.org. http://savannah.gnu.org/cookbook/?func=detailitem&comingfrom=23&item_id=%22%3E%3Cscript%3Ealert(420)%3C/script%3E https://savannah.gnu.org/account/login.php?uri=";>alert(document.cookie