News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Christopher Kunz's Blog:
How to increase PEAR security (and give admins a fuzzy feeling)
November 11, 2005 @ 06:09:47

In this new post from Christopher Kunz today on his blog, he talks a bit about the "lupii" attacks that have been happening and a suggestion for those maintaining the PEAR projects.

The latest PHP worm (lupii) attacks systems that are vulnerable to a remote code execution hole in PEAR::XMLRPC (or phpxmlrpc). It can only propagate on systems whose administrators have neglected to update PHP (or PEAR) in the last 3 months.

What if the PEAR project would introduce a flag for packets, say, "-security" and modify the PEAR installer accordingly. That flag should only be used for pure security fixes, without feature or BC breakage, so that it won't break anything at all (apart from the exploits).

He goes on mentioning that something like this would be a load off of your local web server admin's mind - just run a cron to look at a PEAR security channel and pick up the latest updates...

0 comments voice your opinion now!
pear security xmlrpc lupii pear security xmlrpc lupii


blog comments powered by Disqus

Similar Posts

Pádraic Brady: Getting Ahead In Security By Watching The Neighbours

Community News: Latest PEAR Releases for 10.23.2006

Joshua Eichorn's Blog: HTML_AJAX Wordpress Plugin Tutorial

Zend Developer Zone: Creating Data Tables With PEAR Structures_DataGrid

Joshua Eichorn\'s Blog: Looking for HTML_AJAX Success Stories


Community Events

Don't see your event here?
Let us know!


api library community laravel5 series interview introduction podcast unittest framework opinion language development laravel video version extension voicesoftheelephpant php7 release

All content copyright, 2015 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework