| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 00:00 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 00:02 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 00:04 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 00:05 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 00:06 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 01:50 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 01:51 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 01:52 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 01:54 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 01:56 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 01:57 | |
| travis-ci | Build #100: vboctor/mantisbt Issue17826_upload_path (05e7504) Victor Boctor - The build passed. | 02:11 |
|---|---|---|
| travis-ci | Build details: http://travis-ci.org/vboctor/mantisbt/builds/39669604 | 02:11 |
| travis-ci | Code Changes: https://github.com/vboctor/mantisbt/commit/05e7504b10ea | 02:11 |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 03:41 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 03:45 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 05:29 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 05:33 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 06:55 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 07:27 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 07:28 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 07:33 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 08:43 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 09:13 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 09:13 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 09:18 | |
| *** dregad <dregad!~dregad@77-234.193-178.cust.bluewin.ch> has joined #mantisbt | 10:22 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 10:34 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 10:36 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 10:37 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 10:39 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 10:40 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 10:42 | |
| dregad | paulr you there | 10:45 |
| paulr | . | 11:09 |
| paulr | dregad: just finished helping a kid with their computing home work | 11:09 |
| paulr | so now sitting down to look at reamining stuff | 11:10 |
| dregad | paulr did you get feedback from mitre about swapping cve's ? | 11:29 |
| paulr | yes | 11:29 |
| dregad | so they're OK with it ? | 11:29 |
| dregad | (before I make anything public) | 11:30 |
| paulr | yes, I just forwarded you there response | 11:30 |
| dregad | cheers | 11:30 |
| paulr | (It came whilst I was in restuarant last night - decided not to try forwarding from a mobile) | 11:30 |
| paulr | have you fixed the plugin issue? | 11:30 |
| dregad | especially with your "magic" forward button that sends stuff to the ML :-P | 11:31 |
| dregad | plugin meaning XML ? | 11:31 |
| paulr | still dont know what happeend there | 11:31 |
| paulr | yes | 11:31 |
| paulr | although coudl be work filtering | 11:31 |
| paulr | if I use gitter from work, it doesn't show members list | 11:31 |
| paulr | but at home it does | 11:31 |
| dregad | i have the patch ready, but while testing i found another issue which i'm working on now | 11:31 |
| paulr | heh | 11:32 |
| paulr | I find that alot ;p | 11:32 |
| dregad | yep | 11:32 |
| dregad | FYI I updated #17243 with CVE and made you reporter so you can see it | 11:43 |
| paulr | I met someone from sweden last night i've known online for 10 years | 11:45 |
| dregad | nice | 11:45 |
| paulr | they insisted on paying for dinner | 11:45 |
| paulr | :) | 11:45 |
| paulr | he was over with his kid to london | 11:46 |
| dregad | fancy dinner? | 11:46 |
| paulr | not overly expensive, but we went to http://www.salaam-namaste.co.uk/ | 11:48 |
| paulr | when you coming to london? :P | 11:48 |
| dregad | looks nice | 11:48 |
| paulr | windows is starting to piss me off | 11:49 |
| paulr | "your pc is running low on memory, shall we close firefox?" | 11:50 |
| paulr | Available RAm: 3.5GB | 11:50 |
| paulr | actually, if you could just use the 3.5gb... | 11:50 |
| dregad | ==> linux | 11:50 |
| dregad | enough said | 11:51 |
| paulr | swedish friend just uses mac's now | 11:51 |
| paulr | anyway, i had 3 patches to find and send | 11:51 |
| dregad | ok | 11:51 |
| dregad | i have not gone through the last batch yet | 11:52 |
| paulr | well, 2 to find and 1 to work out what to do as proper fix is in 1.3 | 11:52 |
| paulr | aka move to json | 11:52 |
| dregad | paulr i was chatting with github support following the deletion of your mantisbt fork | 11:59 |
| dregad | since that basically invalidates all the PR's you forked | 11:59 |
| paulr | right | 11:59 |
| dregad | i asked them if they could fix that | 11:59 |
| dregad | they said probably yes, by restoring the fork | 12:00 |
| dregad | but they can only do that "in place" | 12:00 |
| dregad | for which they'd need your approval | 12:00 |
| paulr | yea I guess could approve that | 12:00 |
| dregad | OK, so I'll forward you a mail, if you could reply to them it would be great | 12:01 |
| paulr | gonna get confusing long term anyway :) | 12:01 |
| dregad | what do you mean ? | 12:02 |
| paulr | well, when I launch fork | 12:02 |
| paulr | I dropped other open source projects to focus on mantis | 12:03 |
| dregad | are you on bitbucket ? | 12:05 |
| paulr | yes | 12:05 |
| dregad | i just found out they offer unlimited private repos | 12:05 |
| paulr | I thought it was 5 | 12:06 |
| dregad | so we can use that to share patches if you'd like | 12:06 |
| dregad | no | 12:06 |
| dregad | # of repos is unlimited | 12:06 |
| dregad | they restrict the number of team members | 12:06 |
| paulr | I think i've got 2 accounts ;/ | 12:07 |
| dregad | i just found a grangeway | 12:07 |
| dregad | i assume that's you? | 12:08 |
| paulr | hang on | 12:08 |
| paulr | trying to work out what's me :) | 12:08 |
| dregad | there's also 4 different paul richards | 12:09 |
| dregad | including a "minimoo" one which is probably you as well | 12:09 |
| dregad | anyway let me know which account | 12:09 |
| paulr | right minimoo is the one i want to use | 12:09 |
| paulr | paul_richards is me, but i want to delete that | 12:10 |
| paulr | yep got | 12:11 |
| paulr | you got a branch you ussing? | 12:11 |
| dregad | not yet i just cloned my github fork | 12:11 |
| dregad | so anyway feel free to submit PRs with your patches | 12:12 |
| paulr | ahh right | 12:12 |
| paulr | see pm | 12:21 |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 12:25 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 12:27 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 12:28 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 12:30 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 12:31 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 12:32 | |
| dregad | ok so i cleaned up the bitbucket fork now, leaving only the master* and work-in-progress sec branches | 12:43 |
| paulr | k | 12:53 |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 14:16 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 14:18 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 14:20 | |
| *** dejale___ <dejale___!~dejalexan@87.113.26.154> has joined #mantisbt | 14:21 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 14:21 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 14:22 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 14:22 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 14:24 | |
| *** dejale___ <dejale___!~dejalexan@87.113.26.154> has quit IRC | 14:25 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 14:27 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 16:10 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 16:12 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 16:14 | |
| *** dejale___ <dejale___!~dejalexan@87.113.26.154> has joined #mantisbt | 16:15 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 16:15 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 16:16 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 16:16 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 16:17 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 16:18 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 16:19 | |
| *** dejale___ <dejale___!~dejalexan@87.113.26.154> has quit IRC | 16:19 | |
| *** dejale___ <dejale___!~dejalexan@87.113.26.154> has joined #mantisbt | 16:20 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 16:20 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 16:22 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 16:24 | |
| *** dejale___ <dejale___!~dejalexan@87.113.26.154> has quit IRC | 16:25 | |
| *** Protogenes <Protogenes!~Protogene@dslb-188-106-213-066.188.106.pools.vodafone-ip.de> has quit IRC | 16:47 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 18:08 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 18:13 | |
| *** Protogenes <Protogenes!~Protogene@dslb-188-106-213-066.188.106.pools.vodafone-ip.de> has joined #mantisbt | 18:54 | |
| * paulr wonders how to create a PR to bitbucket | 19:03 | |
| * paulr pokes dregad | 19:04 | |
| dregad | moo | 19:04 |
| dregad | not sure actually, never tried before | 19:04 |
| dregad | would assume you need to fork my repo | 19:04 |
| dregad | then push your local changes to it | 19:04 |
| dregad | (aka same as github) | 19:04 |
| paulr | like that maybe? | 19:07 |
| dregad | yep | 19:07 |
| dregad | thanks for that | 19:12 |
| dregad | how long did it take for you to get the CVE ID back from mitre ? | 19:12 |
| paulr | can you mail me the poc for swf? | 19:12 |
| paulr | <24 hours | 19:12 |
| dregad | wtf is swf ? | 19:12 |
| dregad | ;) | 19:13 |
| paulr | http://www.mantisbt.org/bugs/file_download.php?file_id=5117&type=bug | 19:13 |
| paulr | also see pm | 19:16 |
| dregad | mail sent - not sure I understand what the deal is with this file though | 19:26 |
| dregad | just to clarify - that PR you sent me contains the same fixes we discussed earlier this week (the zip file you sent me via skype ?) | 19:29 |
| * dregad pings paulr | 19:29 | |
| paulr | yes | 19:35 |
| GitHub | [mantisbt] dregad pushed 1 new commit to master-1.2.x: http://git.io/M5Kejw | 19:40 |
| GitHub | mantisbt/master-1.2.x 99ffb0a Damien Regad: SQL injection in mc_project_get_attachments()... | 19:40 |
| GitHub | [mantisbt] dregad pushed 1 new commit to master: http://git.io/rsIrbQ | 19:40 |
| GitHub | mantisbt/master 5faf97a Damien Regad: SQL injection in mc_project_get_attachments()... | 19:40 |
| *** Ragnor <Ragnor!~Ragnor@dslb-146-060-184-044.146.060.pools.vodafone-ip.de> has quit IRC | 19:50 | |
| *** Ragnor <Ragnor!~Ragnor@dslb-094-221-078-034.094.221.pools.vodafone-ip.de> has joined #mantisbt | 19:51 | |
| *** blue6storm <blue6storm!29da9daf@gateway/web/freenode/ip.41.218.157.175> has joined #mantisbt | 19:57 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 19:57 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 19:58 | |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has joined #mantisbt | 20:00 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 20:02 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 20:03 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 20:03 | |
| paulr | dregad: btw, not quire sure i understand that oss-seclist ;) | 20:04 |
| paulr | it seems to me you'd want to email mitre directly, then email oss-sec after | 20:05 |
| *** dejalex__ <dejalex__!~dejalexan@87.113.26.154> has quit IRC | 20:05 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 20:08 | |
| dregad | you're talking about the SQL vulnerability ? | 20:12 |
| dregad | since i pushed the fix, it's now public so I don't see any reason to mail mitre privately and not the public list | 20:14 |
| paulr | I meant in general | 20:24 |
| *** blue6storm <blue6storm!29da9daf@gateway/web/freenode/ip.41.218.157.175> has quit IRC | 20:27 | |
| dregad | it's a way to announce vuln to the public I guess | 20:29 |
| dregad | so yes, 1. mitre and 2. oss-sec | 20:29 |
| dregad | what's your point | 20:30 |
| paulr | mitre seem to suggest going to others and not them directly | 20:30 |
| dregad | that's just because they're lazy I guess ;) | 20:31 |
| dregad | which I suppose is the reason why the dhx told me to mail oss-sec | 20:32 |
| dregad | and consequently I wrote http://www.mantisbt.org/wiki/doku.php/mantisbt:handling_security_problems#obtaining_a_cve_id | 20:32 |
| dregad | to document the process | 20:33 |
| dregad | see also http://oss-security.openwall.org/wiki/mailing-lists/oss-security | 20:34 |
| dregad | anyway doesn't matter that much | 20:34 |
| dregad | it's way too late (again) so going to bed now | 20:34 |
| dregad | good nite | 20:34 |
| paulr | nn | 20:38 |
| *** dregad <dregad!~dregad@77-234.193-178.cust.bluewin.ch> has quit IRC | 20:49 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 21:51 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has joined #mantisbt | 21:52 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 21:56 | |
| *** dejalexa_ <dejalexa_!~dejalexan@87.113.26.154> has quit IRC | 21:57 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has joined #mantisbt | 23:41 | |
| *** dejalexander <dejalexander!~dejalexan@87.113.26.154> has quit IRC | 23:45 | |
Generated by irclog2html.py 2.13.0 by Marius Gedminas - find it at mg.pov.lt!