[wellylug] Strange emails from wellylug website

Ewen McNeill wellylug at ewen.mcneill.gen.nz
Fri Jun 17 09:17:03 NZST 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

As several of you have reported to me, there were several strange email
messages sent out by the Wellylug website (currently hosted on my
webserver synagogue.naos.co.nz) overnight.

These were caused by some people stumbling across a security flaw in the
Wellylug website which allowed them to send out emails from the website.

I have now disabled the pages that I identified as having this problem,
so hopefully this should not occur again.  (Many of you will have
received one more copy this morning, which was me tested to ensure that
I'd identified the correct flaw; I tried to stop as many of those
messages as possible from going out.)

My apologies for the inconvenience caused.

Ewen

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFCsexEppdH5uwbODkRAqTkAKCEfYbG5q6inQGMZxkPwibsIs/KzQCgsos2
0bZX917NPPNa+0vzCr3PhoM=
=+DE3
-----END PGP SIGNATURE-----




More information about the wellylug mailing list