security

Security implications for gallery support in Drupal Publisher

Coming up for SPU, Drupal Publisher, and the Imgblog module is support for galleries, as implemented by the Image Gallery module. This will make use of the blogid parameter in spu.newImage (it’s not just there to look pretty in the specs).

Posted In

CACert, the free certificate authority, needs your lovin'

CAcert Logo

Image via Wikipedia

Have you heard of CACert? It’s a certificate authority, one which is free and uses a web of trust model to verify the identity of its clients, as opposed to notaries, lawyers, credit checks, and such. It’s also free. I signed up for CACert quite some time ago, in order to get a code signing certificate (for Authenticode and document macros).

Posted In

Mods as security holes?

The irrepressible Raymond Chen recently mused about "security holes" that aren't – that is to say, features which may be misused but don't actually cause security vulnerabilities.
While Raymond's blog is always worth reading, this is more about something from one of the comments on this entry. Commenter Erzengel mused that "impersonating a plugin could be an initial delivery system" for malware. For sure, this is a potential entry vector, and I'm honestly surprised that there are very few if any malware mods out there. Given the number of games where you can actually build mods in C/C++ and have access to the system that way, one would expect that the popularity of the games industry would cause malware authors to flock to the idea.

Posted In