Someone wastes Heine's time - He gives them proper credit

in

A little while ago there was this disclosure about a potential Local File Inclusion bug in Drupal core. The issue report was lacking in two areas:

  1. It did not have enough information about how to take advantage of the vulnerability - this is a classic problem with security reports is that they are not complete enough.
  2. It was sent to a public list before being sent to the Drupal security team which could have resulted in a zero-day exploit.

Heine Deelstra took the time to investigate the issue and discuss it with the "researcher" who found it. The result: this mail.

"ZOMG - IF YOU OVERWRITE INDEX.PHP, TEH CODE IS EXECUTED!!!!"

Every security issue sucks up time trying to understand it, verify it, etc. It's nice to have an issue with such a light-hearted resolution.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • You can use Markdown syntax to format and style the text. Also see Markdown Extra for tables, footnotes, and more.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h3> <blockquote> <br>
  • Lines and paragraphs break automatically.

More information about formatting options