Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would love to know how they detected it.


they didn't. some guy reported it on the forum http://forum.piwik.org/read.php?2,97666


Good find. Of course, it just changes my question to: How did he find it?


Either he noticed effects of running the exploit (lic.log file?) or just downloaded the zip to read the code (I do this when some project's VCS doesn't have 'browse source' component or it's web component has no decent syntax highlighting), noticed base64 encoded chunks and got curious. I'd get curious for sure.

All this is really simple and not the real question, which instead is: where were checksums and why not in a safe place?




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: