Quantcast
Channel: General — LowEndTalk
Viewing all articles
Browse latest Browse all 22771

Update your LookingGlass installations!

$
0
0

Seems like the 'industry standard' network looking glass now faces a pretty nasty XSS vulnerability, as seen here.

An RDNS XSS was disclosed which has been patched by a temporary fix (thanks ldrrp). To patch, simply replace LookingGlass/LookingGlass.php with the patched version found here: LookingGlass.php

A maintenance/security release will be issued before 2015-01-26, which will include a number of patches for v1.

An example of the XSS attack:

An example of a patched LG:


Viewing all articles
Browse latest Browse all 22771

Trending Articles