Penetration Testing mailing list archives

Knoppix STD and WMF


From: "Ess H. Sanders" <linux2 () gmail com>
Date: Fri, 13 Jan 2006 10:43:28 -0600

Hi all,
I work with the http://knoppix-std.org/ group, and the current
maintainer asked me to forward this to you.

With regards to the iFrame on the domain.

The fundamental problem was that the founder of the STD project was
and is the domain owner and he is no longer active. He has passed over
the reins for development but he still holds "the keys" to virtually
every part of the hosting.

With this limitation in place it is tricky to operate a site as popular as ours.

I fully admit that we missed the problem because attacks like that are
automatically filtered by various content management proxies by many
of our regulars however once the problem was reported to myself it was
fixed within 60 mins.

We are only human and react just like everyone else on the planet.
Should it have happened... definitely not... could it happen again...
sure it could... if it couldn't there would be no point in any
security distro cause no one could be hacked.

Please keep in mind that we operated with ZERO funding until very
recently. We have started taking donations to allow us to "step up" a
gear and have access to better resources but average donations of
<1Euro a day doesnt get you a lot. Work is in progress for a new
release, it should be very useful to everyone here!

thx

Current thread: