Skip to main content

L33tBlogz - Update for security hole in version 1.0.0

posted onNovember 7, 2001
by hitbsecnews

Told you guys there were bugs in the system! At about 1pm today, deekayen of Thatware.org found a security flaw in the code that allowed anyone to gain admin privs on the system and gain full control of the site. Much thanks to him for finding the flaw and pointing it out as well as major props to DietCoke for giving me the heads up on the 'defacement'. I knew there was something I missed!

Eitherways, I've updated the files and incorporated a more secure approach to the entire system -- there are some changes to the readme.1st file so do read it. The new code can be found in the download section of the site. As always, if anyone finds more bugs, please send your findings to l33tdawg@hackinthebox.org. If you downloaded version 1.0.0 yesterday, make sure you UPGRADE.

Source

Tags

Spam

You May Also Like

Recent News

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th