Archive for October 11th, 2004

Cutenews exploits

I’ve just realized that the fact that Cutenews’ code is public helped hackers to discover some exploits in it. I won’t mention any of the exploits here, that’s not the goal of this entry! Just wanted to tell an advice to Cute users:

Rename your cutenews/ to a personal name which you’ll be the only one to know.

I discovered that the number of potential exploits can be highly reduced if the ‘hacker’ doesn’t know where Cutenews is located.

P.S. - Many exploits in Cute has been fixed in latest versions, but I’m still using 1.3.2 version. So, risks of exploits are lower if you’re using 1.3.5+.

Read more…


Sidebar