public inbox for overseers@sourceware.org
 help / color / mirror / Atom feed
* Forw: Bad Site Appeal Notification
       [not found] ` <ACEB2F88-D0C6-4C66-9934-ADB73FB94EE9@hautesecure.com>
@ 2009-02-09 18:25   ` Frank Ch. Eigler
  2009-02-09 18:26   ` Fwd: " Frank Ch. Eigler
  1 sibling, 0 replies; 4+ messages in thread
From: Frank Ch. Eigler @ 2009-02-09 18:25 UTC (permalink / raw)
  To: Sourceware Overseers

Hi -

On Mon, Feb 09, 2009 at 10:15:20AM -0800, Haute Secure Customer Support wrote:

> I've responded to a couple of mails that have originated from  
> soureware.org regarding the entry in our Online Reputation list for  
> sourceware.org. unfortunately all of them have bounced so far. So i'm  
> resending this mail in the hope that it gets to someone in  
> sourceware.org who can attend to this.

Further:

> Thanks for the mail. The reason that Sourceware.org is on our content
> reputation list is because we have found a significant amount of malicious
> material on the site. It looks like you are running a very old Bugzilla
> installation - 2.17.5 which is over 4 years old and which contains many many
> security vulnerabilities. Malicious attackers target older web based software
> and in the case of your Bugzilla installation they have been creating
> malicious entries designed to infect users browsing the site either directly or
> potentially indirectly via hidden iFrames on other sites.
> 
> Below is an example of one of the infected URLs that should help you research
> and resolve the issue.
> 
> h*p : / / sourceware [dot] org / bugzilla / attachment [dot] cgi?id=1988
> 
> You should consider upgrading to the 3.2 release of Bugzilla which has just
> been released and contains a massive number of fixes for various security
> vulnerabilities.


- FChE

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Fwd: Bad Site Appeal Notification
       [not found] ` <ACEB2F88-D0C6-4C66-9934-ADB73FB94EE9@hautesecure.com>
  2009-02-09 18:25   ` Forw: Bad Site Appeal Notification Frank Ch. Eigler
@ 2009-02-09 18:26   ` Frank Ch. Eigler
       [not found]     ` <6C5CFABD-4766-438C-BA66-A1FE2A4740BE@hautesecure.com>
  2009-02-09 19:57     ` Fwd: " Daniel Berlin
  1 sibling, 2 replies; 4+ messages in thread
From: Frank Ch. Eigler @ 2009-02-09 18:26 UTC (permalink / raw)
  To: Haute Secure Customer Support; +Cc: Sourceware Overseers

Hi -

Just to be clear, are you claiming that upgrading our bugzilla to 3.2
would remove and/or make impossible further spam attachments?  Did
your software find actual *malware* or only spam links to it?

- FChE

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Bad Site Appeal Notification
       [not found]     ` <6C5CFABD-4766-438C-BA66-A1FE2A4740BE@hautesecure.com>
@ 2009-02-09 18:39       ` Frank Ch. Eigler
  0 siblings, 0 replies; 4+ messages in thread
From: Frank Ch. Eigler @ 2009-02-09 18:39 UTC (permalink / raw)
  To: Haute Secure Customer Support; +Cc: Sourceware Overseers

Hi -

> i can make no absolute guarantees about upgrading to the latest  
> version of Bugzilla, but Mozilla has made significant security  
> improvements since the Bugzilla 2.x releases and our system has not  
> found malicious content in Bugzilla 3.2 installations.

> we have found actual malicious content in your bugzilla

Can you supply some links?  The only one sent so far was spam that
appeared to link outward.  We should be able to zap them without
actual major sysadmin effort that would be required by a speculative
bugzilla upgrade.

- FChE

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Fwd: Bad Site Appeal Notification
  2009-02-09 18:26   ` Fwd: " Frank Ch. Eigler
       [not found]     ` <6C5CFABD-4766-438C-BA66-A1FE2A4740BE@hautesecure.com>
@ 2009-02-09 19:57     ` Daniel Berlin
  1 sibling, 0 replies; 4+ messages in thread
From: Daniel Berlin @ 2009-02-09 19:57 UTC (permalink / raw)
  To: Frank Ch. Eigler; +Cc: Haute Secure Customer Support, Sourceware Overseers

Humorously, there is in fact, a bug Mozilla is about to notify the
world about which shows that even 3.2 is not secure at all for
attachments.
They plan on trying to require people serve attachments from a
different hostname, in fact.

So upgrading to 3.2 will not fix our problems here.

On Mon, Feb 9, 2009 at 1:26 PM, Frank Ch. Eigler <fche@redhat.com> wrote:
> Hi -
>
> Just to be clear, are you claiming that upgrading our bugzilla to 3.2
> would remove and/or make impossible further spam attachments?  Did
> your software find actual *malware* or only spam links to it?
>
> - FChE
>

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2009-02-09 19:57 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <F80FD039-A46E-4CC2-955C-5B0FF41E5B9D@hautesecure.com>
     [not found] ` <ACEB2F88-D0C6-4C66-9934-ADB73FB94EE9@hautesecure.com>
2009-02-09 18:25   ` Forw: Bad Site Appeal Notification Frank Ch. Eigler
2009-02-09 18:26   ` Fwd: " Frank Ch. Eigler
     [not found]     ` <6C5CFABD-4766-438C-BA66-A1FE2A4740BE@hautesecure.com>
2009-02-09 18:39       ` Frank Ch. Eigler
2009-02-09 19:57     ` Fwd: " Daniel Berlin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).