[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: MP1 Security issue


On 3/26/07, Robert Landrum <suppressed> wrote:
Despite the (perceived) violation of protocol, Randal's message did
light a fire under the asses of a lot of mod_perl developers, and made
known a potential security issue.  I'd say that's mission accomplished.

That's easy to say in this specific case, since the actual threat is
so tiny that it didn't make much difference.  You guys probably
wouldn't think it was such a good idea if it had been a more serious
exploit and someone had used it to compromise your servers before a
fix was available.

- Perrin


Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.