[IMC-Tech] Can Someone Switch rochester.indymedia.org to point to new site
Ben Dean-Kawamura
ben.dean.kawamura at gmail.com
Mon Nov 6 21:14:10 PST 2006
Thanks for the advice. The dada version was 0.99.3, but I ran the
auto-update module and there were a ton of updates. I don't have easy
access to IE, can you double check that my update fixed the problem?
Ben
On 11/6/06, Alster <alster at indymedia.org> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hi Andy,
>
> sacco at riseup.net wrote:
> > The new Rochester, NY Indymedia site is ready. Can someone switch the
> > DNS "rochester.indymedia.org" to point to 216.221.91.142? (BTW,
> > Thanks John for being so helpful with this process.)
>
> You don't seem to be running the latest dadaimc version on the new site:
> The following URL, when copied + pasted into Internet Explorer (6 or 7)
> or Konqueror, will spawn a Warning message, which demonstrates a
> vulnerability.
>
> http://hamiltonsites.ca/mod/search/dosearch/index.php?dosearch=1&medium=&searchtext=<script>alert('This_is_not_the_latest_dadaimc_version_but_an_outdated_one_which_is_vulnerable_to_Cross_Site_Scripting.')</script>
>
> Alster
> - --
> GPG key
> http://keys.indymedia.org/cgi-bin/lookup?op=get&search=05059C17
> Fingerprint 1B8B 128F 8435 541C B3A5 1B7E CF5A 9D55 0505 9C17
> All other http://docs.indymedia.org/view/Main/AlsteR
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
>
> iD8DBQFFT0FSz1qdVQUFnBcRAs0ZAJ0eEpxuAPo87NS+B7VcdLVi5n6+PgCfRDFp
> bNDtzljagPMZutx6/ctiTZU=
> =emlR
> -----END PGP SIGNATURE-----
> _______________________________________________
> imc-tech mailing list
> imc-tech at lists.indymedia.org
> http://lists.indymedia.org/mailman/listinfo/imc-tech
>
More information about the imc-tech
mailing list