Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 28 Oct 2008 10:50:17 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request phpmyadmin (Fwd: XSS in phpMyadmin)

Am Dienstag 28 Oktober 2008 schrieb Thijs Kinkhorst:
> Do we still call things that require register_globals to be on a
> 'vulnerability'?
>
> Register_globals has been advertised (including in the PHP documentation
> of that option) as a very bad idea for many years now, it's turned off by
> default since years aswell. Turning it on could be considered as knowingly
> taking the risk on a certain class of exploits.
>
> At least Debian doesn't provide any security support for these issues.

I'd think this is okay as a policy for a distribution and agree that it's a 
very bad idea to enable register_globals these days (afaik it should go away 
in php6 anyway). But anyway a register_globals issue most likely leads to at 
least some bad programming practise (using uninitalized variables), I think 
it's okay to still track them.

And beside, would be worth a check but I am pretty sure there are still lot's 
of webhosters out there having it enabled.


-- 
Hanno Böck		Blog:		http://www.hboeck.de/
GPG: 3DBD3B20		Jabber/Mail:	hanno@...eck.de

http://x1000malquer.de/ - ab 8.11. Atomtransporte stoppen

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ