|
|
|
|
|
by quakershake
4288 days ago
|
|
Anyone who bashes open source code for bugs is an idiot. Maybe the "community" should start auditing code instead of blogging and tweeting about how awful things are. This functionality has been around for so long it is generational. +1 to the person(s) responsible for finding this. Everyone complaining should stfu |
|
However weev is completely correct in telling people that shell environment variables were an obviously bad place for arbitrary data set by people on the internet back in the 90s. The shell wasn't designed for that, it's known to be insecure.
HNs defence of Apache doing silly things seems to be more love of Apache and lack of knowledge of Unix fundamentals than hate of free tools.