Re: in search for XML-RPC developers/maintainers contact
| From: | Daniel Convissor | Date: | Tue, 30 Aug 2005 14:45:49 +0000 |
| Subject: | Re: in search for XML-RPC developers/maintainers contact | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39629@lists.php.net to get a copy of this message | ||
Hi Folks:
On Mon, Aug 29, 2005 at 11:17:58AM +0200, anatoly techtonik wrote:
> 3. A lot of troubles with this package in the past even with lead developer
> Dan, who potentially should knew the package weaknesses, but didn't do
> anything to close them without third-party patch submissions. For the last
> year many PHP products removed support for XML-RPC because of major security
> flaws. These include WordPress, Drupal and to my surprise even Mozilla site
> was hacked thanks to this bug.
Anatoly, how about putting down your axe? You have ground it so much that
it no longer has a sharp point.
Every single PHP implementation of the XML_RPC protocol I've seen is based
on the phpxmlrpc stuff, including PEAR's version. Every one of them had
the vulnerabilities.
As far as Drupal and WordPress, it seems they never used the PEAR
implementation:
http://cvs.drupal.org/viewcvs/drupal/drupal/includes/xmlrpc.inc?rev=1.24&view=log
http://cvs.sourceforge.net/viewcvs.py/cafelog/wordpress/xmlrpc.php?rev=1.43&view=log
Regarding Mozilla's site, I assume you're talking about the Spread Firefox
site. That site uses Drupal, which, as mentioned above, does not use
PEAR's XML_RPC.
http://www.mozillazine.org/talkback.html?article=6947
--Dan
--
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
data intensive web and database programming
http://www.AnalysisAndSolutions.com/
4015 7th Ave #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409