<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1143969814964735268.comments</id><updated>2012-05-30T11:35:57.707-07:00</updated><category term='drupal'/><category term='port scan'/><category term='full path disclosure'/><category term='mod_security'/><category term='zero day bug'/><category term='free web security scanner'/><title type='text'>Kyplex Cloud Security Blog</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.kyplex.com/feeds/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/comments/default'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Kyplex Cloud Security Blog</name><uri>http://www.blogger.com/profile/13504218104415284464</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1143969814964735268.post-2123873227495946960</id><published>2010-04-28T16:57:50.384-07:00</published><updated>2010-04-28T16:57:50.384-07:00</updated><title type='text'>Definitely a feature, not a bug. No Drupal install...</title><summary type='text'>Definitely a feature, not a bug. No Drupal installation is or could possibly be ready-to-go as soon as it is installed. Drupal is a framework; it requires configuration to make it do what you want it to. And if you&amp;#39;re configuring things, you should be able to see where the problem is. Before you take your site live you can turn off the helpfulness.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/2123873227495946960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/2123873227495946960'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html?showComment=1272499070384#c2123873227495946960' title=''/><author><name>Ice</name><uri>http://www.blogger.com/profile/03232585151096666730</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html' ref='tag:blogger.com,1999:blog-1143969814964735268.post-3569592220486384265' source='http://www.blogger.com/feeds/1143969814964735268/posts/default/3569592220486384265' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-161233408'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.displayTime' value='April 28, 2010 4:57 PM'/></entry><entry><id>tag:blogger.com,1999:blog-1143969814964735268.post-1893573153169082920</id><published>2010-04-28T14:34:19.306-07:00</published><updated>2010-04-28T14:34:19.306-07:00</updated><title type='text'>Also:

&amp;quot;This [files] directory is fully writa...</title><summary type='text'>Also:&lt;br /&gt;&lt;br /&gt;&amp;quot;This [files] directory is fully writable as it is used as a temporary directory.&amp;quot;&lt;br /&gt;&lt;br /&gt;That is not accurate. The files directory must be writable by the webserver, and ideally is not world-writable. It also is not used as a temp directory. Drupal explicitly uses an alternativel location for temporary file storage (usually /tmp like anything in linux, but </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/1893573153169082920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/1893573153169082920'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html?showComment=1272490459306#c1893573153169082920' title=''/><author><name>Outlandish Josh</name><uri>http://jmk226.myopenid.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html' ref='tag:blogger.com,1999:blog-1143969814964735268.post-3569592220486384265' source='http://www.blogger.com/feeds/1143969814964735268/posts/default/3569592220486384265' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1316335536'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.displayTime' value='April 28, 2010 2:34 PM'/></entry><entry><id>tag:blogger.com,1999:blog-1143969814964735268.post-1494872902470295163</id><published>2010-04-28T14:23:22.207-07:00</published><updated>2010-04-28T14:23:22.207-07:00</updated><title type='text'>Um... this is a feature. 

Drupal installs with er...</title><summary type='text'>Um... this is a feature. &lt;br /&gt;&lt;br /&gt;Drupal installs with errors written to the screen to help people debug any install problems. Before going into production, everyone should be turning this off:&lt;br /&gt;&lt;br /&gt;http://drupal.org/node/22239</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/1494872902470295163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/1494872902470295163'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html?showComment=1272489802207#c1494872902470295163' title=''/><author><name>Outlandish Josh</name><uri>http://jmk226.myopenid.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html' ref='tag:blogger.com,1999:blog-1143969814964735268.post-3569592220486384265' source='http://www.blogger.com/feeds/1143969814964735268/posts/default/3569592220486384265' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1316335536'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.displayTime' value='April 28, 2010 2:23 PM'/></entry><entry><id>tag:blogger.com,1999:blog-1143969814964735268.post-2778146279916045336</id><published>2010-04-28T14:22:53.622-07:00</published><updated>2010-04-28T14:22:53.622-07:00</updated><title type='text'>Hello Jo

You do not need to enable &amp;quot;display ...</title><summary type='text'>Hello Jo&lt;br /&gt;&lt;br /&gt;You do not need to enable &amp;quot;display errors on screen&amp;quot; because it is enabled by default.&lt;br /&gt;&lt;br /&gt;Drupal displays errors to screen by default.&lt;br /&gt;&lt;br /&gt;Hope this is clear now.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/2778146279916045336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/2778146279916045336'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html?showComment=1272489773622#c2778146279916045336' title=''/><author><name>ZeroDayScan Blog</name><uri>http://www.blogger.com/profile/13504218104415284464</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html' ref='tag:blogger.com,1999:blog-1143969814964735268.post-3569592220486384265' source='http://www.blogger.com/feeds/1143969814964735268/posts/default/3569592220486384265' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2057966148'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.displayTime' value='April 28, 2010 2:22 PM'/></entry><entry><id>tag:blogger.com,1999:blog-1143969814964735268.post-7405673697601927677</id><published>2010-04-28T13:31:36.826-07:00</published><updated>2010-04-28T13:31:36.826-07:00</updated><title type='text'>For the records, the above disclosure was discusse...</title><summary type='text'>For the records, the above disclosure was discussed publicly in the Drupal bug tracker at http://drupal.org/node/783618</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/7405673697601927677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/7405673697601927677'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html?showComment=1272486696826#c7405673697601927677' title=''/><author><name>scor</name><uri>http://scorlosquet.myopenid.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html' ref='tag:blogger.com,1999:blog-1143969814964735268.post-3569592220486384265' source='http://www.blogger.com/feeds/1143969814964735268/posts/default/3569592220486384265' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1001679771'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.displayTime' value='April 28, 2010 1:31 PM'/></entry><entry><id>tag:blogger.com,1999:blog-1143969814964735268.post-7985038487634355440</id><published>2010-04-28T13:30:04.885-07:00</published><updated>2010-04-28T13:30:04.885-07:00</updated><title type='text'>So if I summarize this: If you enable &amp;quot;displa...</title><summary type='text'>So if I summarize this: If you enable &amp;quot;display errors on screen&amp;quot;, then Drupal shows errors on screen.&lt;br /&gt;whaw, you made a great discovery !</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/7985038487634355440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1143969814964735268/3569592220486384265/comments/default/7985038487634355440'/><link rel='alternate' type='text/html' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html?showComment=1272486604885#c7985038487634355440' title=''/><author><name>Jo Wouters</name><uri>http://www.blogger.com/profile/00189358537850544469</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kyplex.com/2010/04/full-path-disclosure-bug-in-drupal-616.html' ref='tag:blogger.com,1999:blog-1143969814964735268.post-3569592220486384265' source='http://www.blogger.com/feeds/1143969814964735268/posts/default/3569592220486384265' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-84616467'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.displayTime' value='April 28, 2010 1:30 PM'/></entry></feed>
