Closed (won't fix)
Project:
PHPIDS
Version:
6.x-1.11
Component:
Miscellaneous
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
30 Aug 2010 at 13:32 UTC
Updated:
31 Aug 2010 at 22:26 UTC
I don't know if someone is hijacking the website or if PHPIDS is just got a poor arrangement but according to my security software they are using a certificate that is issued by an UNKNOWN Certificate Authority. Anybody have any ideas on what the deal is?
These downloads include PHP code and XML strings that contain complex regular expressions like those used in MOD_REWRITE. I haven't looked to analyze them but if security has been compromised then the code could become malicious at some point.
Comments
Comment #1
it-cruPHP-IDS.ORG website used this type of certificate since I'm using and developing the drupal phpids module.
I'll sent Matthias from PHP-IDS.ORG an information so he could try to change this. This problem is only possible to solved by PHP-IDS.ORG website publisher itself, so status is changed to closed (won't fix) or better can't fix ;)