TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

What we discovered by scanning 235 OSS apps for security issues

17 点作者 fmavituna大约 12 年前

6 条评论

jimktrains2大约 12 年前
That was terribly devoid of data and the only link in the article links back to their paid app. The choice in colors of the pie chart was just terrible.<p>Also, what do databases have to do with anything? Obviously MySQL would be heavily used since it's commonly used with PHP and other web frameworks.<p>Also, how is their scanner false positive free?
评论 #5595804 未加载
评论 #5595651 未加载
city41大约 12 年前
I don't understand how SQL injection still exists as a problem. Isn't it pretty much completely solved by using an ORM or prepared statements? Is it just laziness that allows it to fester on, or is there something I'm missing?
评论 #5595492 未加载
评论 #5595438 未加载
fmavituna大约 12 年前
Sorry about the lack of disclosing the raw data, here is the document that infographic produced from:<p><a href="https://docs.google.com/a/mavitunasecurity.com/spreadsheet/ccc?key=0Ai3Dfx3aMZQ9dEJiemw0UE9TS0tUemdldVNTWG5MR2c" rel="nofollow">https://docs.google.com/a/mavitunasecurity.com/spreadsheet/c...</a><p>You can see the list of all scanned applications with versions and brief information about the results, including the advisory link (if published).<p>From advisory you can see technical details of the vulnerabilities, i.e. <a href="http://www.mavitunasecurity.com/xss-and-blind-sql-injection-vulnerabilities-in-exponentcms/" rel="nofollow">http://www.mavitunasecurity.com/xss-and-blind-sql-injection-...</a><p>List of all advisories from us (all found by Netsparker)<p><a href="http://www.mavitunasecurity.com/netsparker-advisories/" rel="nofollow">http://www.mavitunasecurity.com/netsparker-advisories/</a>
ambiate大约 12 年前
Your tinfoil hat should start buzzing when you see the word 'infographic.' Instead of data to backup the analysis, you should expect back links to a product or website (possibly far from the topic).<p>It is a well known art that infographics are highly popular on voting sites and a cheap way to build quality back links.
评论 #5595654 未加载
skytalon大约 12 年前
Not really on topic, but in that article, why would the paragraph "title" texts made up of images? (that appear to be in-page data).
jdbevan大约 12 年前
Shame this isn't an unbiased/independent report.