By maozet on
Hello
Take a look at the following post covering a security vulnerability found in Drupal 6.16.
http://blog.zerodayscan.com/2010/04/full-path-disclosure-bug-in-drupal-6...
Best regards,
Maoz
Hello
Take a look at the following post covering a security vulnerability found in Drupal 6.16.
http://blog.zerodayscan.com/2010/04/full-path-disclosure-bug-in-drupal-6...
Best regards,
Maoz
Comments
_
Knowing that a website is installed at /var/www/drupal-6.16 is hardly a major discovery :-)
Arrival of the Narcissistic Vulnerability Pimps
Sadly as Drupal becomes more popular we are going to see more and more examples of "Narcissistic Vulnerability Pimps" coming onto the scene and trying to get their day in the spotlight. This just creates more noise and confusion around Drupal, which is a waste of time and attention.
(Narcissistic Vulnerability Pimps is a phrase coined recently by the Verizon Security Blog.)
To claim that this "information disclosure" is a vulnerability when it is a sensible default that is easily disabled is a real shame.
--
Morris Animal Foundation
on further reflection
I realize that this doesn't fit the "classic" definition of "Narcissistic Vulnerability Pimps" because it was disclosed "responsibly".
So, it's not truly a vulnerability does that make the more appropriate term just "Narcissistic Pimps" ?
--
Morris Animal Foundation
_
Interesting article - for those pointing out default settings as a 'vulnerability' in order to appear Big and Clever I prefer the four-letter term pronounced 2@ :-)
fix
This Drupal 6 issue is being fixed at http://drupal.org/node/783618
By design
I doubt it will be fixed. This is simply whoring a config error to advertise a "security scanner".
Now, if they find something interesting, then trumpet to the world, by all means. But this is insincere at best.