<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VHCS v2.4.7.1 Pro &#8211; DO NOT USE</title>
	<atom:link href="http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/feed/" rel="self" type="application/rss+xml" />
	<link>http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/</link>
	<description>Enhancing your Ubuntu experience!</description>
	<lastBuildDate>Fri, 11 May 2012 05:04:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Cliff Wells</title>
		<link>http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/#comment-14659</link>
		<dc:creator>Cliff Wells</dc:creator>
		<pubDate>Wed, 16 Mar 2011 07:47:28 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=140#comment-14659</guid>
		<description>I found major SQL injection paths in VHCS back in 2005.  The developers accepted my patches, but didn&#039;t seem to quite grasp the severity of the issue (my initial bug report was downgraded) until I submitted an exploit to SecurityTracker, then they became very eager to understand the issue.  I spent an entire weekend changing literally hundreds of lines of code to force their SQL through a common function that properly sanitized and escaped their queries.   I submitted this and was rewarded with complaints that a couple of pages no longer functioned.  I checked and I&#039;d omitted a semicolon on those pages.   Nevermind that I had warned them about the rush job I&#039;d done and that they&#039;d need to review all the functionality since I didn&#039;t use all of it myself.

Anyway, I was left with a bad taste about both their attention to security and their rather unwelcome response to my initial bug report.   I avoid them now.  It&#039;s too bad since it&#039;s a rather nice interface.

http://securitytracker.com/id/1013703</description>
		<content:encoded><![CDATA[<p>I found major SQL injection paths in VHCS back in 2005.  The developers accepted my patches, but didn&#8217;t seem to quite grasp the severity of the issue (my initial bug report was downgraded) until I submitted an exploit to SecurityTracker, then they became very eager to understand the issue.  I spent an entire weekend changing literally hundreds of lines of code to force their SQL through a common function that properly sanitized and escaped their queries.   I submitted this and was rewarded with complaints that a couple of pages no longer functioned.  I checked and I&#8217;d omitted a semicolon on those pages.   Nevermind that I had warned them about the rush job I&#8217;d done and that they&#8217;d need to review all the functionality since I didn&#8217;t use all of it myself.</p>
<p>Anyway, I was left with a bad taste about both their attention to security and their rather unwelcome response to my initial bug report.   I avoid them now.  It&#8217;s too bad since it&#8217;s a rather nice interface.</p>
<p><a href="http://securitytracker.com/id/1013703" rel="nofollow">http://securitytracker.com/id/1013703</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nadeem</title>
		<link>http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/#comment-7506</link>
		<dc:creator>Nadeem</dc:creator>
		<pubDate>Mon, 15 Dec 2008 17:00:15 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=140#comment-7506</guid>
		<description>Go for SysCp instead of VHCS</description>
		<content:encoded><![CDATA[<p>Go for SysCp instead of VHCS</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wendy</title>
		<link>http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/#comment-7497</link>
		<dc:creator>Wendy</dc:creator>
		<pubDate>Sat, 13 Dec 2008 16:11:57 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=140#comment-7497</guid>
		<description>Can you advise a replacement of VHCS?</description>
		<content:encoded><![CDATA[<p>Can you advise a replacement of VHCS?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: junksiu</title>
		<link>http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/#comment-5651</link>
		<dc:creator>junksiu</dc:creator>
		<pubDate>Sun, 10 Aug 2008 05:14:43 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=140#comment-5651</guid>
		<description>VHCS don&#039;t even host a forum now. So sad...</description>
		<content:encoded><![CDATA[<p>VHCS don&#8217;t even host a forum now. So sad&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: User</title>
		<link>http://ubuntu-tutorials.com/2006/08/15/vhcs-v2471-pro-do-not-use/#comment-110</link>
		<dc:creator>User</dc:creator>
		<pubDate>Wed, 28 Nov 2007 20:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=140#comment-110</guid>
		<description>if you want to use it you should customize it, to cover all the security holes. ;) i find it quite simple to correct the code. hint: find a php programmer with some server administration skills.</description>
		<content:encoded><![CDATA[<p>if you want to use it you should customize it, to cover all the security holes. <img src='http://ubuntu-tutorials.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  i find it quite simple to correct the code. hint: find a php programmer with some server administration skills.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: basic (User agent is rejected)
Database Caching 2/6 queries in 0.004 seconds using disk: basic
Object Caching 263/265 objects using disk: basic

Served from: ubuntu-tutorials.com @ 2012-05-23 13:05:51 -->
