Cracking Drupal - zomg http://crackingdrupal.com/taxonomy/term/3/0 en Someone wastes Heine's time - He gives them proper credit http://crackingdrupal.com/blog/greggles/someone-wastes-heines-time-he-gives-them-proper-credit <p>A little while ago there was <a href="http://seclists.org/bugtraq/2009/Feb/0064.html">this disclosure</a> about a potential Local File Inclusion bug in Drupal core. The issue report was lacking in two areas:</p> <ol> <li>It did not have enough information about how to take advantage of the vulnerability - this is a classic problem with security reports is that they are not complete enough.</li> <li>It was sent to a public list before being sent to the <a href="http://drupal.org/security-team">Drupal security team</a> which could have resulted in a zero-day exploit.</li> </ol> <p><a href="http://heine.familiedeelstra.com/">Heine Deelstra</a> took the time to investigate the issue and discuss it with the "researcher" who found it. The result: <a href="http://www.securityfocus.com/archive/1/501032">this mail</a>.</p> <blockquote><p>"ZOMG - IF YOU OVERWRITE INDEX.PHP, TEH CODE IS EXECUTED!!!!"</p></blockquote> <p>Every security issue sucks up time trying to understand it, verify it, etc. It's nice to have an issue with such a light-hearted resolution.</p> http://crackingdrupal.com/blog/greggles/someone-wastes-heines-time-he-gives-them-proper-credit#comments zomg Wed, 18 Feb 2009 22:50:21 +0000 greggles 11 at http://crackingdrupal.com