Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This was posted a few days ago, probably related:

"sourceforge entry point seems still active."

http://seclists.org/fulldisclosure/2011/Jan/424

http://extraexploit.blogspot.com/2011/01/sourceforge-entry-p...



As far as I could tell, that post was just about one specific SF project that had a vulnerable PHP CMS installed on their web space. It's possible that the more general problem of projects being allowed to install/manage their own software got leveraged into a larger exploit, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: