/srv/irclogs.ubuntu.com/2008/07/12/#ubuntu-website.txt

emgenthello there.02:30
emgentnewz2000: ping bout Bug 24761202:31
ubot3emgent: Bug 247612 on http://launchpad.net/bugs/247612 is private02:31
emgents/bout/about/02:31
pierrelourenshello03:14
newz2000h I emgent, I see it03:27
newz2000did you find this on your own or is this a widely known problem?03:27
emgent0dd.03:28
newz2000ok, thanks for reporting it privately03:29
newz2000emgent: has this been reported to MoinMoin team?03:30
newz2000(that you know of)03:30
emgenthttp://moinmoin.wikiwikiweb.de/?action=fullsearch&context=180&value=XSS&titlesearch=Titoli03:31
emgentknow issue do not include it.03:31
emgentnewz2000: what version of moinmoin is up on help.u.c ?03:33
newz20001.6.303:33
emgentmoin 1.6.303:35
emgentNone yet.03:35
emgenthttp://moinmo.in/SecurityFixes03:35
emgentnewz2000: seems that upstream it`snt vulnerable03:36
emgentok it is.03:38
newz2000it is vulnerable?03:38
newz2000they're running 1.7.0 on moinmo.in03:38
emgentmoinmo.in is vulnerable.03:40
emgentmoinmoin.wikiweb.de is not because is in read-only mode.03:41
emgentbut generally it`s a 0day bug.03:41
newz2000emgent: how did you discover it?03:41
emgentnewz2000: my box03:41
emgentauditing.03:41
emgentnewz2000: http://launchpad.net/~ubuntu-whitehat03:42
pierrelourensnewz2000, Do you ever stop working? ;)03:42
newz2000I hate it when this stuff happens on a Friday night. I'm going to have to call someone and wake them up03:42
newz2000pierrelourens: I checked back in to publish the announcement for alpha 2 release03:42
emgentnewz2000: anyway if for you it`s ok i will talk with upstream for try to coordinate a fix and advisory.03:43
newz2000yes, please do03:43
newz2000discretely, white-hatish of course.03:44
newz2000like with us, and thanks. :-)03:44
emgentsure :)03:44
emgentnewz2000: np, it`s funny for me :)03:44
emgentnewz2000: anyway why we dont use mod-security ?03:49
newz2000I don't know, this server is not actually under my control, I just maintain its theme03:50
emgentah ok03:50
newz2000but I have the cell phone # of the person who is in control03:50
newz2000I'm having some people on our team look at it to decide the level of risk03:50
emgentRick Clark ?03:50
newz2000no, but I should try him since he's in my time zone03:50
newz2000or near it03:51
emgentanyway dont worry03:51
emgentit`s a low risk03:51
emgentnow it`s 0day.03:51
emgentbig idle in moin-dev argh03:52
newz2000yeah, everyon'es in europe03:53
emgentme too :)03:53
emgenthere 4.53 am03:53
emgentpierrelourens: please fix your client :)04:11
pierrelourensit's fixed. I was messing with crap :)04:12
emgentheheh04:12
pierrelourensxchat was wonky04:12
emgentswitch to irssi04:13
newz2000emgent: there are better places to harass people than #ubuntu-website04:13
newz2000if you don't mind :-)04:14
emgentheheh sorry newz2000 :)04:14
pierrelourensI didn't feel harassed, for the record04:14
pierrelourens:)04:14
melat0ninlol @ 'bragging rights' in EDGE -- why would someone brag about their timezone?10:23
melat0ninnewz2000: i'm going to spend alittle time now looking through the ubuntu site for any typos etc.  How big does somethng need to be before it should be reported as a bug?14:58
melat0ninfor example: http://www.ubuntu.com/support - under Buy Professional Support Services, the first sentence should really be two sentences.  The placement of the comma is wrong grammatically.14:59
newz2000melat0nin: hi, if you think it needs fixed, go ahead and report it and we'll make get it resolved. Trick is to try and put the right amount of info in the bug report so that a fix can be applied as simply as posible.16:05
melat0ninnewz2000: okay will do16:06
melat0ninnewz2000: I don't want to tread on people's toes by submitting lots of style-related bugs, but there are some areas where the ubuntu.com website text is not good at all (even if it's grammatically correct) from a writing-for-the-web point of view18:04
melat0ninIs there anything I can do to help this? I'm very conscious of the risk of offending people18:04

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!