| ||||||||||||
![]() |
![]() |
| | LinkBack | Thread Tools | Search this Thread | Display Modes |
(#1)
|
(#2)
|
| Senior Member Posts: 5,573 Join Date: Jun 2005 Location: Cumbria, UK |
16-05-2007, 12:46 PM
This is a good point. Maybe Jamie can bring it to the attention of Varun. A good idea would be to have a company like Gulftech (http://www.gulftech.org) audit the software and point out areas where security needs improving. Icon Headquarters - Its Elixir - Web2Messenger |
| | |
(#3)
|
| Chief Executive Officer Posts: 2,829 Join Date: May 2003 |
16-05-2007, 01:18 PM
Quote:
We are definately serious about security and would have released a stable build immediately if it wasnt for the following two reasons: 1) The XSS vulnerabilities reported are from POST variables if I remember which is generally considered a low risk as the potential hacker needs to redirect the user using a form. 2) We were ready to release the stable but some delays in the Winapp builds have pushed it back. In fact, the PHP team has been waiting for the updated stable Winapps to mark the build as stable. A new stable build should be out by this week approximately. Let me know if there is anything else. Regards, Varun Shoor -------------------------------------------------------------------
| |
| | |
(#4)
|
(#5)
|
| Operations Manager Posts: 5,266 Join Date: Jan 2006 Location: United Kingdom |
16-05-2007, 07:08 PM
Hi Neal, The XSS flaw that has been fixed has nothing to do with automated comment posting. Most robots that execute this spamming can also (usually) defeat most CAPTCHA effortlessly - computers can read better than people can, so this is not an end-all solution. You may find this useful: Disabling comments and stopping comment spam -------------------------------------------------------------------
|
| | |
![]() |
| Tags |
| committed |
| Thread Tools | Search this Thread |
| Display Modes | |
| |