Campfire... damnit...
Posted by Nicholas Tue, 30 Jan 2007 13:57:00 GMT
Well, a few weeks back I posted about some potential security issues with Campfire.
As it turns out there are a few more interesting issues that we hadn’t yet found at that time. While we were messing around to see if you could put avatars in names via image tags, we discovered that certain places in Campfire were not replacing entities on the html, and were therefore running it. To some this issue may seem trivial, but I suggest that it’s actually potentially more dangerous than the issues discussed in my previous post....
finish reading 'Campfire... damnit...'