Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:15803 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 72457 invoked by uid 1010); 5 Apr 2005 01:28:24 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 72422 invoked from network); 5 Apr 2005 01:28:23 -0000 Received: from unknown (HELO ter.dk) (127.0.0.1) by localhost with SMTP; 5 Apr 2005 01:28:23 -0000 X-Host-Fingerprint: 213.237.67.135 213.237.67.135.adsl.by.worldonline.dk Linux 2.4/2.6 Received: from ([213.237.67.135:12809] helo=mail.ter.dk) by pb1.pair.com (ecelerity HEAD r(5268)) with SMTP id 2F/F3-19272-6B9E1524 for ; Mon, 04 Apr 2005 21:28:22 -0400 Received: from workpenguin (workpenguin [192.168.1.32]) by mail.ter.dk (Symaskine) with SMTP id 361D58A4010 for ; Tue, 5 Apr 2005 03:28:13 +0200 (CEST) To: internals@lists.php.net Date: Tue, 05 Apr 2005 03:28:00 +0200 Message-ID: <89q351tbc0a60jo4mdonnup7be2v3ud2ad@4ax.com> References: <20050404043233.GV32563@arvo.suso.org> <4250C42F.7070608@lerdorf.com> <20050404045058.GW32563@arvo.suso.org> In-Reply-To: X-Mailer: Forte Agent 1.91/32.564 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable Subject: Re: [PHP-DEV] Should I report this bug/exploit? From: php@ter.dk (Peter Brodersen) On Mon, 4 Apr 2005 09:13:04 +0200 (CEST), in php.internals derick@php.net (Derick Rethans) wrote: >> Is that a publically accessable mailing list or does it just go to a >> few people? > >Only a few people. .. but don't expect any kind of feedback :-) (yeah, I know - I'm still yackin' about the print_r(glob("{/home/currentuser/,/etc/}*",GLOB_BRACE)) issue combined with the glob file name disclosure issue) --=20 - Peter Brodersen