[02:30] hello there. [02:31] newz2000: ping bout Bug 247612 [02:31] emgent: Bug 247612 on http://launchpad.net/bugs/247612 is private [02:31] s/bout/about/ [03:14] hello [03:27] h I emgent, I see it [03:27] did you find this on your own or is this a widely known problem? [03:28] 0dd. [03:29] ok, thanks for reporting it privately [03:30] emgent: has this been reported to MoinMoin team? [03:30] (that you know of) [03:31] http://moinmoin.wikiwikiweb.de/?action=fullsearch&context=180&value=XSS&titlesearch=Titoli [03:31] know issue do not include it. [03:33] newz2000: what version of moinmoin is up on help.u.c ? [03:33] 1.6.3 [03:35] moin 1.6.3 [03:35] None yet. [03:35] http://moinmo.in/SecurityFixes [03:36] newz2000: seems that upstream it`snt vulnerable [03:38] ok it is. [03:38] it is vulnerable? [03:38] they're running 1.7.0 on moinmo.in [03:40] moinmo.in is vulnerable. [03:41] moinmoin.wikiweb.de is not because is in read-only mode. [03:41] but generally it`s a 0day bug. [03:41] emgent: how did you discover it? [03:41] newz2000: my box [03:41] auditing. [03:42] newz2000: http://launchpad.net/~ubuntu-whitehat [03:42] newz2000, Do you ever stop working? ;) [03:42] I hate it when this stuff happens on a Friday night. I'm going to have to call someone and wake them up [03:42] pierrelourens: I checked back in to publish the announcement for alpha 2 release [03:43] newz2000: anyway if for you it`s ok i will talk with upstream for try to coordinate a fix and advisory. [03:43] yes, please do [03:44] discretely, white-hatish of course. [03:44] like with us, and thanks. :-) [03:44] sure :) [03:44] newz2000: np, it`s funny for me :) [03:49] newz2000: anyway why we dont use mod-security ? [03:50] I don't know, this server is not actually under my control, I just maintain its theme [03:50] ah ok [03:50] but I have the cell phone # of the person who is in control [03:50] I'm having some people on our team look at it to decide the level of risk [03:50] Rick Clark ? [03:50] no, but I should try him since he's in my time zone [03:51] or near it [03:51] anyway dont worry [03:51] it`s a low risk [03:51] now it`s 0day. [03:52] big idle in moin-dev argh [03:53] yeah, everyon'es in europe [03:53] me too :) [03:53] here 4.53 am [04:11] pierrelourens: please fix your client :) [04:12] it's fixed. I was messing with crap :) [04:12] heheh [04:12] xchat was wonky [04:13] switch to irssi [04:13] emgent: there are better places to harass people than #ubuntu-website [04:14] if you don't mind :-) [04:14] heheh sorry newz2000 :) [04:14] I didn't feel harassed, for the record [04:14] :) [10:23] lol @ 'bragging rights' in EDGE -- why would someone brag about their timezone? [14:58] newz2000: i'm going to spend alittle time now looking through the ubuntu site for any typos etc. How big does somethng need to be before it should be reported as a bug? [14:59] for example: http://www.ubuntu.com/support - under Buy Professional Support Services, the first sentence should really be two sentences. The placement of the comma is wrong grammatically. [16:05] melat0nin: hi, if you think it needs fixed, go ahead and report it and we'll make get it resolved. Trick is to try and put the right amount of info in the bug report so that a fix can be applied as simply as posible. [16:06] newz2000: okay will do [18:04] newz2000: I don't want to tread on people's toes by submitting lots of style-related bugs, but there are some areas where the ubuntu.com website text is not good at all (even if it's grammatically correct) from a writing-for-the-web point of view [18:04] Is there anything I can do to help this? I'm very conscious of the risk of offending people