Salta al contenuto
0
  • Categorie
  • Recenti
  • Tag
  • Popolare
  • Mondo
  • Utenti
  • Gruppi
  • Categorie
  • Recenti
  • Tag
  • Popolare
  • Mondo
  • Utenti
  • Gruppi
Collassa

Forum Federato

Di Piero Bosio
  1. Home
  2. Categorie
  3. Senza categoria
  4. the reported version of a server software is not necessarily indicative of it being vulnerable to an exploit or not, the software may have had a fix backported or had been deployed in a configuration where the vulnerability wasn’t relevant.

the reported version of a server software is not necessarily indicative of it being vulnerable to an exploit or not, the software may have had a fix backported or had been deployed in a configuration where the vulnerability wasn’t relevant.

Pianificato Fissato Bloccato Spostato Senza categoria
3 Post 3 Autori 0 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Topic risposta
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • Ariadne Conill 🐰:therian:undefined Questo utente è esterno a questo forum
    Ariadne Conill 🐰:therian:undefined Questo utente è esterno a questo forum
    Ariadne Conill 🐰:therian:
    scritto su ultima modifica di
    #1

    the reported version of a server software is not necessarily indicative of it being vulnerable to an exploit or not, the software may have had a fix backported or had been deployed in a configuration where the vulnerability wasn’t relevant.

    reporting something based on just a version string and writing a clickbait article about how the person ignored you is just shitty behavior

    Ryan Finnieundefined Nicolás Alvarezundefined 2 Risposte Ultima Risposta
    1
    • Ariadne Conill 🐰:therian:undefined Ariadne Conill 🐰:therian:

      the reported version of a server software is not necessarily indicative of it being vulnerable to an exploit or not, the software may have had a fix backported or had been deployed in a configuration where the vulnerability wasn’t relevant.

      reporting something based on just a version string and writing a clickbait article about how the person ignored you is just shitty behavior

      Ryan Finnieundefined Questo utente è esterno a questo forum
      Ryan Finnieundefined Questo utente è esterno a questo forum
      Ryan Finnie
      scritto su ultima modifica di
      #2

      @ariadne See also: bargain basement PCI compliance scanning companies. I have a side client where we have as much configured (Apache etc) to strip version numbers from the public responses. Not for security through obscurity, but to hide them from the vendor which doesn't know what those weird "-4ubuntu13" strings are at the end of our MASSIVELY INSECURE SOFTWARE FAIL FAIL FAIL

      Edit: just saw what this was was subtooting, and yeah, pretty much what I expected, ugh

      1 Risposta Ultima Risposta
      1
      • Ariadne Conill 🐰:therian:undefined Ariadne Conill 🐰:therian:

        the reported version of a server software is not necessarily indicative of it being vulnerable to an exploit or not, the software may have had a fix backported or had been deployed in a configuration where the vulnerability wasn’t relevant.

        reporting something based on just a version string and writing a clickbait article about how the person ignored you is just shitty behavior

        Nicolás Alvarezundefined Questo utente è esterno a questo forum
        Nicolás Alvarezundefined Questo utente è esterno a questo forum
        Nicolás Alvarez
        scritto su ultima modifica di
        #3

        @ariadne KDE regularly receives reports like "Severity: High, directory listing is enabled on https://amarok.kde.org/images/", usually begging for bounties. I guess they think automated security scanners are get rich quick schemes they can use.

        1 Risposta Ultima Risposta
        1
        • Oblomovundefined Oblomov ha condiviso questa discussione
        Rispondi
        • Topic risposta
        Effettua l'accesso per rispondere
        • Da Vecchi a Nuovi
        • Da Nuovi a Vecchi
        • Più Voti


        • Accedi

        • Accedi o registrati per effettuare la ricerca.
        • Primo post
          Ultimo post