Kayako logo
Comments, Questions & Feedback Non product related discussion, feedback and questions about Kayako.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
NC Software Offline
Member
 
NC Software's Avatar
 
Posts: 507
Join Date: Dec 2005
Location: Sitting
Are you committed to security? - 16-05-2007, 12:26 PM

I see in the change log there is a XSS fix. If there is a security flaw in the software, why isn't a new stable release brought out immediately? vBulletin is a fine example of a company committed to security, if there is a potential for a XSS attack, a new version is immediately released.


Neal Culiner
NC Software, Inc.
3.30.02 STABLE
   
Reply With Quote
  (#2) Old
craigbrass Offline
Senior Member
 
Posts: 5,326
Join Date: Jun 2005
Location: Cumbria, UK
16-05-2007, 12:46 PM

This is a good point. Maybe Jamie can bring it to the attention of Varun.

A good idea would be to have a company like Gulftech (http://www.gulftech.org) audit the software and point out areas where security needs improving.


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger
   
Reply With Quote
  (#3) Old
Varun Shoor Offline
Chief Executive Officer
 
Varun Shoor's Avatar
 
Posts: 2,829
Join Date: May 2003
16-05-2007, 01:18 PM

Quote:
Originally Posted by NC Software View Post
I see in the change log there is a XSS fix. If there is a security flaw in the software, why isn't a new stable release brought out immediately? vBulletin is a fine example of a company committed to security, if there is a potential for a XSS attack, a new version is immediately released.
Hi Neal,
We are definately serious about security and would have released a stable build immediately if it wasnt for the following two reasons:

1) The XSS vulnerabilities reported are from POST variables if I remember which is generally considered a low risk as the potential hacker needs to redirect the user using a form.

2) We were ready to release the stable but some delays in the Winapp builds have pushed it back. In fact, the PHP team has been waiting for the updated stable Winapps to mark the build as stable.

A new stable build should be out by this week approximately. Let me know if there is anything else.

Regards,

Varun Shoor


Varun Shoor (varun.shoor ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#4) Old
NC Software Offline
Member
 
NC Software's Avatar
 
Posts: 507
Join Date: Dec 2005
Location: Sitting
16-05-2007, 06:04 PM

As much spam hits my KB area comments boxes it does concern me! Maybe you can add CAPTCHA image requirements to comment submissions and that will help add another layer of security? Or give us the option (requested previously) of turning off "Add a Comment" to KB areas, etc. and we can prevent anyone from injecting into our sites via that approach. The best security is prevention first! Then handling the input second.


Neal Culiner
NC Software, Inc.
3.30.02 STABLE
   
Reply With Quote
  (#5) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,033
Join Date: Jan 2006
Location: United Kingdom
16-05-2007, 07:08 PM

Hi Neal,

The XSS flaw that has been fixed has nothing to do with automated comment posting.

Most robots that execute this spamming can also (usually) defeat most CAPTCHA effortlessly - computers can read better than people can, so this is not an end-all solution.

You may find this useful: Disabling comments and stopping comment spam


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
Reply

Tags
committed

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46