Hello

Take a look at the following post covering a security vulnerability found in Drupal 6.16.

http://blog.zerodayscan.com/2010/04/full-path-disclosure-bug-in-drupal-6...

Best regards,
Maoz

Comments

pbarnett’s picture

Knowing that a website is installed at /var/www/drupal-6.16 is hardly a major discovery :-)

greggles’s picture

Sadly as Drupal becomes more popular we are going to see more and more examples of "Narcissistic Vulnerability Pimps" coming onto the scene and trying to get their day in the spotlight. This just creates more noise and confusion around Drupal, which is a waste of time and attention.

(Narcissistic Vulnerability Pimps is a phrase coined recently by the Verizon Security Blog.)

To claim that this "information disclosure" is a vulnerability when it is a sensible default that is easily disabled is a real shame.

greggles’s picture

I realize that this doesn't fit the "classic" definition of "Narcissistic Vulnerability Pimps" because it was disclosed "responsibly".

So, it's not truly a vulnerability does that make the more appropriate term just "Narcissistic Pimps" ?

pbarnett’s picture

Interesting article - for those pointing out default settings as a 'vulnerability' in order to appear Big and Clever I prefer the four-letter term pronounced 2@ :-)

scor’s picture

This Drupal 6 issue is being fixed at http://drupal.org/node/783618

heine’s picture

I doubt it will be fixed. This is simply whoring a config error to advertise a "security scanner".

Now, if they find something interesting, then trumpet to the world, by all means. But this is insincere at best.