Forum Moderators: bakedjake

Message Too Old, No Replies

Looksmart Grub Has a Hacker Exploit Bug

A hacker may be able to gain unauthorized access to Grub user credential

         

martinibuster

6:02 am on Aug 9, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



From SecurityFocus [securityfocus.com], July 14th:

It has been reported that Grub does not sufficiently secure sensitive information. Because of this, an attacker may be able to gain unauthorized access to Grub user credentials.

Eww. Glad I didn't download that.

Cheers, baby!
;) Y

flea_au

7:54 am on Aug 9, 2003 (gmt 0)

10+ Year Member



martinibuster,

Funny how you say all that without even doing proper research.

Details both the problem and the solution. [securityfocus.com]

It has been reported that this issue is resolved in version 1.4.3 of the Grub client.

From here [securityfocus.com].

Cheers.

jeremy goodrich

5:37 pm on Aug 11, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Bwahah a ha ha haha, that is so funny!

Yes, sure - they fixed it. But, can they crawl robots.txt correctly? :) Nope.

Security bugs, crawl bugs, my oh my - looks like they need to look again eh?

martinibuster

6:40 pm on Aug 11, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Eeww. I'm still glad I didn't download it.

Not everybody may be aware that a security bug exists- even less so that a fix exists.

Asta la vista, baby!
;)

stechert

11:31 pm on Aug 11, 2003 (gmt 0)

10+ Year Member



Actually, though we had some trouble immediately after acquiring Grub (and we had to throttle the system during that time), we're retrieving all robots.txt files 3 times a week now and if you want, you can update your entries in the DB immediately via a simple web form.

Cheers,
Andre

jeremy goodrich

11:34 pm on Aug 11, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hey Andre - nice to see you!

Did legal remove the restriction on your posting here as you mentioned before...?

And, fyi, a lot of us got a note from another bloke over at Look regarding your robots.txt handling...recently ;)

So, I'll believe it's fixed when we go, say, 3 months here @ WebmasterWorld without somebody saying your bot triggered their spider trap.

stechert

11:44 pm on Aug 11, 2003 (gmt 0)

10+ Year Member



Hi Jeremy,

Restrictions are the same -- I will always keep posts to items that are non-material/public info.

Re: the robots.txt challenge, I'm excited for us to live up to it. I'll take a peek around to see what's going on with the other robots.txt handling issue. We've had a quite a few folks report problems on our own boards, but a fair number of them (about 75%) turn out to be issues like "I banned your robot from my site...oops I banned you from robots.txt too", or "Here's my site, oops, my hosting service forwards robots.txt to their robots.txt", or really bad problems with syntax (as your own analysis has shown).

That's why we think the best solution is absolute transparency in the operation of Grub. If you've got a question about what's going on with robots.txt we should just show you via the system. It's taking a little time to get the "cadillac" version in place, but I hope you'll all be pleased.

Cheers,
Andre

jeremy goodrich

3:42 am on Aug 12, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hm, but no comment on how many people are still running the vulnerable client, I suppose? ;)