Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
TacticalMalice
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
TacticalMalice
12y ago
In addition, the issue was leaked pre-announcement among a great many parties who had time to prepare.
32.
▲
by
TacticalMalice
12y ago
> There has never been a recorded case of a virus evolving a completely new transmission mode. Keep in mind that there's a lot that we don't know Ebola and how it behaves in different hosts. For all we know, it may be able to s
33.
▲
by
TacticalMalice
12y ago
The key was used to name expanded placeholders. The intent was to get "placeholder_1", "placeholder_2" ... "placeholder_N" in the query for the number of elements in the argument array. However, arrays can have
34.
▲
by
TacticalMalice
12y ago
> now suddenly put thousands of installations at risk There's a solution that goes with the advisory. You cannot provide a patch without putting sites at risk. Furthermore, the vulnerability was present since the Drupal 7.0 release,
35.
▲
by
TacticalMalice
12y ago
Drupal.org was a qa testcase for the patch.
36.
▲
by
TacticalMalice
12y ago
The problem here is that placeholders are added to the query itself to match the amount of array items. These newly constructed placeholders inadvertently contained user data.
37.
▲
by
TacticalMalice
12y ago
Drupal.org is patched and has been for weeks.
38.
▲
by
TacticalMalice
12y ago
This is "ZOMG take action immediately" bad. - Exploitable by anyone able to access the site - No mitigation - Remote code execution - Stealthy - Exploits are in the wild