Re: in search for XML-RPC developers/maintainers contact

From: Date: Tue, 30 Aug 2005 14:45:49 +0000
Subject: Re: in search for XML-RPC developers/maintainers contact
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39629@lists.php.net to get a copy of this message
Hi Folks: On Mon, Aug 29, 2005 at 11:17:58AM +0200, anatoly techtonik wrote: > 3. A lot of troubles with this package in the past even with lead developer > Dan, who potentially should knew the package weaknesses, but didn't do > anything to close them without third-party patch submissions. For the last > year many PHP products removed support for XML-RPC because of major security > flaws. These include WordPress, Drupal and to my surprise even Mozilla site > was hacked thanks to this bug. Anatoly, how about putting down your axe? You have ground it so much that it no longer has a sharp point. Every single PHP implementation of the XML_RPC protocol I've seen is based on the phpxmlrpc stuff, including PEAR's version. Every one of them had the vulnerabilities. As far as Drupal and WordPress, it seems they never used the PEAR implementation: http://cvs.drupal.org/viewcvs/drupal/drupal/includes/xmlrpc.inc?rev=1.24&view=log http://cvs.sourceforge.net/viewcvs.py/cafelog/wordpress/xmlrpc.php?rev=1.43&view=log Regarding Mozilla's site, I assume you're talking about the Spread Firefox site. That site uses Drupal, which, as mentioned above, does not use PEAR's XML_RPC. http://www.mozillazine.org/talkback.html?article=6947 --Dan -- T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y data intensive web and database programming http://www.AnalysisAndSolutions.com/ 4015 7th Ave #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409

« previous php.pear.dev (#39629) next »