Beefy Boxes and Bandwidth Generously Provided by pair Networks
Keep It Simple, Stupid
 
PerlMonks  

Re^4: Patch an old Perl version

by demerphq (Chancellor)
on Nov 10, 2013 at 23:18 UTC ( #1061934=note: print w/ replies, xml ) Need Help??


in reply to Re^3: Patch an old Perl version
in thread Patch an old Perl version

Sorry, but I do not believe it is responsible to reveal the attack key set at this time. Everybody on the perl5-security list has seen the full attack set and can confirm what I say about it. The fact they rolled security releases for all the major versions should be sufficient proof.

---
$world=~s/war/peace/g


Comment on Re^4: Patch an old Perl version
Re^5: Patch an old Perl version
by BrowserUk (Pope) on Nov 10, 2013 at 23:31 UTC
    I do not believe it is responsible to reveal the attack key set at this time.

    If you attack a url on my machine; I'm the only one who could see the key set. You're accusing me of being a risk.


    With the rise and rise of 'Social' network sites: 'Computers are making people easier to use everyday'
    Examine what is said, not who speaks -- Silence betokens consent -- Love the truth but pardon error.
    "Science is about questioning the status quo. Questioning authority".
    In the absence of evidence, opinion is indistinguishable from prejudice.
      very interesting. As yet admitted, the technical points of this discussion are, by far, deeper to reach for me. But..
      in my serendipity perl experience i ever though Perl had not to be patched: may be upgraded but was not something like a browser (a new minor release every 20 requests...).

      Now i read about an obscure bug about HASH implementation: uh i'm interested! i use old CGIs, my programs use many complex data structures, and i like a lot hashes (quite often i end with stuff like: ${ $first{second}{third} }->[23] ).
      ok. good guy spotted the bug and realesed a patch. normally i download it, read some instruction, and apply it. Seems this is not that case. Better a full upgrade. to be sure.

      BrowserUK: i read carefully many of your posts and i trust you as many other monks here. I learned that your posts, many times, seems like porcupines in a morbid wool thread: but this appearence is not due to a polemic spirit but to a critic one. You think with your brain and before you accept some explication you need to be convinced yourself and prove it. this is the rigth approach of scientinst and many times your dissentient affirmations putted me on a safer way.

      That said, on the other side, in the learning process, is fundamental to trust the 'master' or the 'teacher' or the 'book' (as you prefear). I'm happy that demerphq and other peoples had not shouted on the net about the feasibilty of an hash or rehash attack: i don't want a pletora of bots be in queue in front of my 80 doors.. i prefear the vulnerabilty be known when my son will use Perl 6.8.

      thanks to all for the intersting discussion.

      L*

      There are no rules, there are no thumbs..
      Reinvent the wheel, then learn The Wheel; may be one day you reinvent one of THE WHEELS.
        in the learning process, is fundamental to trust the 'master' or the 'teacher' or the 'book'

        I'm not learning here, I'm challenging. See the last two lines of my sig.


        With the rise and rise of 'Social' network sites: 'Computers are making people easier to use everyday'
        Examine what is said, not who speaks -- Silence betokens consent -- Love the truth but pardon error.
        "Science is about questioning the status quo. Questioning authority".
        In the absence of evidence, opinion is indistinguishable from prejudice.

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://1061934]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others drinking their drinks and smoking their pipes about the Monastery: (13)
As of 2014-10-21 19:35 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    For retirement, I am banking on:










    Results (107 votes), past polls