Slashdot Mirror


Firm To Release Database, Web Server 0-Days

krebsonsecurity writes "January promises to be a busy month for Web server and database administrators alike: A security research firm in Russia says it plans to release information about a slew of previously undocumented vulnerabilities in several widely-used commercial software products, including MySQL, Tivoli, IBM DB2, Sun Directory, and a host of others, writes krebsonsecurity.com. From the blog: 'After working with the vendors long enough, we've come to conclusion that, to put it simply, it is a waste of time. Now, we do not contact with vendors and do not support so-called "responsible disclosure" policy,' Legerov said."

8 of 220 comments (clear)

  1. Re:What's up with the confusing article title? by gregarican · · Score: 3, Funny

    Perhaps the firm is issuing a malicious DROP DATABASE T-SQL command, escaping through some unsanitized web query...

  2. Is it just me? by gregarican · · Score: 4, Funny

    Or is the English language dying a painful death on /. as time passes. The past day's article summaries and headlines are a blend between Yoda backing off the chronic and the broken English that some toy assembly manuals convey.

    Seriously, it took me three passes at reading this article headline to understand what the hell it meant. Maybe that's part of the entertainment value that I'm missing???

    1. Re:Is it just me? by Arancaytar · · Score: 5, Funny

      You got stuck on the DROP DATABASE, didn't you. Happens to a lot of db developers. :P

  3. Re:What's up with the confusing article title? by Arancaytar · · Score: 4, Funny

    We're lucky Slashdot properly escapes its SQL input. Aa headline like "Firm to 'DROP DATABASE `web_server`" might otherwise result in havoc. :P

  4. Re:What's up with the confusing article title? by gregarican · · Score: 3, Funny

    So let me get this straight. Slashdot validates their SQL input. But they don't validate their HTML conformance?

  5. What about bobby tables? by 0100010001010011 · · Score: 4, Funny

    This guy should rename his name to Bobby Tables at the same time. Imagine the number of newspapers that would try to do a press release, but couldn't.

  6. Re:What's up with the confusing article title? by tftp · · Score: 4, Funny

    PS: wikipedia was complaint, its should applauded for its effort.

    What have I done to deserve this pain?

  7. Re:What's up with the confusing article title? by ais523 · · Score: 3, Funny

    I can't figure out if you came up against Muphry's Law there, or if Slashdot's parsing decided to do it for you...

    --
    (1)DOCOMEFROM!2~.2'~#1WHILE:1<-"'?.1$.2'~'"':1/.1$.2'~#0"$#65535'"$"'"'&.1$.2'~'#0$#65535'"$#0'~#32767$#1"