Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
LukasReschke
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
LukasReschke
11y ago
The archive.org links were used at the creation of the blog post. (which was not necessarily the release date ;-) - needed to find some time to write it) So Wordpress is an interesting example. Because the CVE assignment date has nothing to
32.
▲
HTTP GZIP Compression remote date and time leak
(jcarlosnorte.com)
118 points
by
LukasReschke
11y ago
|
34 comments
33.
▲
GitHub supports now issue templates
12 points
by
LukasReschke
11y ago
|
3 comments
34.
▲
Distribution packages considered insecure
(statuscode.ch)
4 points
by
LukasReschke
11y ago
|
1 comments
35.
▲
Subtle vulnerabilities with PHP and cURL
(statuscode.ch)
3 points
by
LukasReschke
11y ago
|
0 comments
36.
▲
Use ownCloud provided Packages, then VM, then Zip, no distro packages
(blog.jospoortvliet.com)
3 points
by
LukasReschke
11y ago
|
1 comments
37.
▲
Collabora Brings LibreOffice Online to OwnCloud
(owncloud.org)
9 points
by
LukasReschke
11y ago
|
1 comments
38.
▲
by
LukasReschke
11y ago
> The one column at the link with that has "medium" and "low" values is "complexity" which means CVSS's "access complexity". So it means there are many vulnerabilities that are easy to exploit
39.
▲
by
LukasReschke
11y ago
So, if we ignore all lower and medium severity ones we're basically only left with CVE-2015-2213 which requires authentication. Also XSS is barely something one can blame PHP for. That's pretty low number. For the record: ownCloud
40.
▲
by
LukasReschke
11y ago
> that doesn't really scale There are deployments out there with a ton of users. For example Sciebo: https://owncloud.com/customer/sciebo/ / http://sciebo.de/projekt/index.html
41.
▲
by
LukasReschke
11y ago
We also have some nice graphs about the speed of PHP 7: https://owncloud.org/blog/php-7-is-here-and-owncloud-is-read...
42.
▲
by
LukasReschke
11y ago
> logging changes "Please look at this commit so you know how you can hack us", sounds certainly like a much better idea ;-) > Security history at Wordpress When was there a single very grave vulnerability within the core of
43.
▲
Western Digital and OwnCloud Team Up to Bring OwnCloud to Home Users
(owncloud.org)
128 points
by
LukasReschke
11y ago
|
84 comments
44.
▲
by
LukasReschke
11y ago
That was actually the part where they partially mitigated the vulnerability with. So before it was more insecure. The green one is the "fix" :) The constant time comparison is pretty irrelevant here. Check https://githu
45.
▲
by
LukasReschke
11y ago
> I run ownCloud, despite some reservations about its security. I'm not too concerned about the data in ownCloud itself (if it's private, then I encrypt it client-side, but most things I put in ownCloud are not very private). I
46.
▲
by
LukasReschke
11y ago
> Owncloud is cool but very buggy ! Sorry that you experienced bugs. Just to ensure that we fix any potential bug: Could you file those as described at https://github.com/owncloud/core/blob/master/CONT
47.
▲
by
LukasReschke
11y ago
> Seafile has a much smaller attack surface (no PHP, MySQL not required, etc) ownCloud does run a successful Bug Bounty program and is paying for security bugs: https://hackerone.com/owncloud Also I have published a blog
48.
▲
by
LukasReschke
11y ago
> Here's their 'Records of security issues' page: https://seacloud.cc/group/3/wiki/security-records/ Just take a look who reported their recent issue allowing a lot of attack vectors. (
49.
▲
Symfony Polyfill: Userland Backport of PHP Features
(github.com)
1 points
by
LukasReschke
11y ago
|
0 comments
50.
▲
Disclosed Netgear Router Vulnerability Under Attack
(threatpost.com)
5 points
by
LukasReschke
11y ago
|
0 comments