28 ms·
This is part of what the developer released to fix the security vulnerability disclosed responsibly on WHT [1] tl;dr of that thread by the OP [2] . Beyond the r
by sikhnerd 13y ago
This is part of what the developer released to fix the security vulnerability disclosed responsibly on WHT [1] tl;dr of that thread by the OP [2] . Beyond the ridiculous response of the developer in the thread, the fix released doesn't even fix the issue. Some other security researcher released the root vuln [3] and basically every install of this software is about to be rooted. And that's all before the ridiculousness of passing a root password over http, which strips "special characters" that is used to login to your box and upgrade their software. If you read the linked thread, it's like a case study on how to NOT respond to a security disclosure.
[1] - http://www.webhostingtalk.com/showthread.php?t=1275572 http://www.webhostingtalk.com/showthread.php?t=1275572
[2] - http://www.webhostingtalk.com/showpost.php?p=8727714&postcount=148 http://www.webhostingtalk.com/showpost.php?p=8727714&postcou...
[3] - http://localhost.re/p/zamfoo-120-vulnerability http://localhost.re/p/zamfoo-120-vulnerability
- DCoder 13y agoSee also discussion on Reddit [1] and a particularly interesting comment [2]. [1] http://www.reddit.com/r/programming/comments/1gfve8/how_not_to_handle_a_critical_security/ http://www.reddit.com/r/programming/comments/1gfve8/how_not_... [2] http://www.reddit.com/r/programming/comments/1gfve8/how_not_to_handle_a_critical_security/cajwaja http://www.reddit.com/r/programming/comments/1gfve8/how_not_...
- justincormack 13y agoAlso a clear case of how not to write software, I mean the architecture is just designed for insecurity. Always been very suspicious of the whole class of "control panel" software from a security angle.