IRC logs of #mantisbt for Tuesday, 2014-08-12

*** kirillka <kirillka!~Miranda@195.242.142.17> has joined #mantisbt00:58
*** Kunda <Kunda!~sphenoid@cpe-68-201-94-52.stx.res.rr.com> has quit IRC01:23
*** giallu__ <giallu__!~giallu@adsl-ull-231-36.40-151.net24.it> has joined #mantisbt03:03
*** giallu_ <giallu_!~giallu@fedora/giallu> has joined #mantisbt03:53
*** giallu_ is now known as giallyu03:55
*** giallyu is now known as giallu03:55
*** giallu__ <giallu__!~giallu@adsl-ull-231-36.40-151.net24.it> has quit IRC03:55
*** giallu_ <giallu_!~giallu@fedora/giallu> has joined #mantisbt04:39
*** giallu <giallu!~giallu@fedora/giallu> has quit IRC04:39
*** mantisbot <mantisbot!~supybot@fluffy.mantisbt.org> has joined #mantisbt05:13
*** giallu_ <giallu_!~giallu@fedora/giallu> has quit IRC07:38
*** lazar2606 <lazar2606!5345a6eb@gateway/web/freenode/ip.83.69.166.235> has joined #mantisbt08:25
*** lazar2606 <lazar2606!5345a6eb@gateway/web/freenode/ip.83.69.166.235> has quit IRC08:27
*** tururu <tururu!5345a6eb@gateway/web/freenode/ip.83.69.166.235> has joined #mantisbt08:40
*** tururu <tururu!5345a6eb@gateway/web/freenode/ip.83.69.166.235> has left #mantisbt08:40
*** lazar2606 <lazar2606!5345a6eb@gateway/web/freenode/ip.83.69.166.235> has joined #mantisbt08:49
paulrmutes: moo10:55
paulrmuts *10:55
mutshey paulr, how goes?10:55
paulrnot too bad10:55
paulryou disabled the profile bit on your tracker right?10:55
mutsyes, i found the config parameters for it and disabled it.10:56
paulrcan you reenable it for 5 minutes?10:56
mutssure, let me do that now and ping you here.10:56
mutsdone.10:57
paulr<option value=""></option><option value="79">&quot;&gt;&lt;img src=x onerror=prompt(1);&gt; &quot;&gt;&lt;img src=x onerror=prompt(1);&gt; &quot;&gt;&lt;img src=x one</option><option value="3">10:59
paulrok, so that looks ok...10:59
mutsit looks like the actual xss is triggered when you open up the "OS options" just before you submit the bug.10:59
paulrahh, I see now11:00
paulrit does a xmlhttprequest11:00
paulrand returns <ul><li>"><img src=x onerror=prompt(1);></li></ul>11:00
paulrso now why didn't that happen locally11:00
paulryou can change your config back if you want11:00
*** lazar2606 <lazar2606!5345a6eb@gateway/web/freenode/ip.83.69.166.235> has quit IRC11:01
paulrhttps://github.com/mantisbt/mantisbt/commit/b77ea9cd2333f1549eea03f020da574747a2a85511:03
mutsthanks11:03
paulrwell11:03
paulrhang on11:03
paulrOK so in 201011:04
paulrwe replace 'projax' with using jquery11:04
paulrand as part of that rework, we return the string json_encoded (But not escaped)11:04
paulrand preasumably jquery itself or something we've also changed at some point is then escaping the string before displaying in browser11:05
paulrso yet again, this basically comes back to the fact there's a lot of improvements in master and we've never done a release11:06
paulrright, added 2 bugnotes to the issue that for everyone else11:10
paulrone with a potential fix, but I'll leave someone else to validate that ;p11:10
mutswhen's the next release?11:13
mutsand why the wait ?11:13
paulrthat's probably more politics then anything else11:26
*** Kunda <Kunda!~sphenoid@214.sub-70-195-202.myvzw.com> has joined #mantisbt11:28
mutswell, i for one am eagerly waiting for the next release.11:39
mutsand applaud you guys for responding so quickly11:40
paulrwe seem to have issues "shipping" code to end users11:41
paulras opposed to writing code11:41
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has quit IRC11:41
mutsour bug bounty programs brings out the bugs from the woodwork in various projects, and few if any respond s quick as you do.11:41
paulrsure, but fixing it in git / identifying the issue and getting end users running it are two different things :)11:43
paulrwe pretty good at the first bit!11:44
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has joined #mantisbt11:48
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has quit IRC11:53
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has joined #mantisbt11:55
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has quit IRC12:09
*** Kunda <Kunda!~sphenoid@214.sub-70-195-202.myvzw.com> has quit IRC12:16
*** Kunda <Kunda!~sphenoid@249.sub-70-195-198.myvzw.com> has joined #mantisbt12:25
*** Kunda <Kunda!~sphenoid@249.sub-70-195-198.myvzw.com> has quit IRC12:46
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has joined #mantisbt13:03
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt14:07
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt14:22
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has joined #mantisbt15:21
*** Protogenes <Protogenes!~Protogene@dslb-188-106-220-078.188.106.pools.vodafone-ip.de> has quit IRC15:31
*** kirillka <kirillka!~Miranda@195.242.142.17> has quit IRC15:47
*** tururu <tururu!5d51ef71@gateway/web/freenode/ip.93.81.239.113> has joined #mantisbt15:57
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has quit IRC17:16
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt17:22
*** Ragnor <Ragnor!~Ragnor@dslb-146-060-077-079.146.060.pools.vodafone-ip.de> has quit IRC17:35
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has quit IRC18:37
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt18:41
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has quit IRC20:15
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt20:17
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has quit IRC21:13
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt21:54
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has quit IRC22:09
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has joined #mantisbt22:44
*** Kunda <Kunda!~sphenoid@172-11-122-212.lightspeed.austtx.sbcglobal.net> has quit IRC22:48
*** suntouch123 <suntouch123!7286ba3b@gateway/web/freenode/ip.114.134.186.59> has joined #mantisbt22:53
suntouch123022:54
*** suntouch123 <suntouch123!7286ba3b@gateway/web/freenode/ip.114.134.186.59> has quit IRC22:54
*** Kunda <Kunda!~sphenoid@cpe-68-201-94-52.stx.res.rr.com> has joined #mantisbt23:59

Generated by irclog2html.py 2.13.0 by Marius Gedminas - find it at mg.pov.lt!