Comment on Using SVN makes your site extremely vulnerableComments−cousin_it16yRussian speaker here, I'll translate some selected comments for your convenience.harm: We need more people who, upon finding a hole, go on to scan the whole Runet, for no nefarious reasons but just to warn unwitting site owners.SilenceAndy: In olden times such people were called hackers, until journalists perverted that word to mean cyber criminals.grayhex: This comment is impervious to Google Translate.cancel: Google inurl:.svn/entries, lots of interesting stuff.Nirvanko: This ain't new, see http://www.adamgotterer.com/2009/01/26/hacking-the-svn-direc... SynteZ: IIS doesn't have this vulnerability :-) By default it doesn't send files without extensions, because it doesn't know the mime type.varyen: Funny, Wii disks from SEGA also have .svn folders, though they're empty.crazywebdev: Now I know how http://vkontakte.ru came about.
Comments
Russian speaker here, I'll translate some selected comments for your convenience.
harm: We need more people who, upon finding a hole, go on to scan the whole Runet, for no nefarious reasons but just to warn unwitting site owners.
SilenceAndy: In olden times such people were called hackers, until journalists perverted that word to mean cyber criminals.
grayhex: This comment is impervious to Google Translate.
cancel: Google inurl:.svn/entries, lots of interesting stuff.
Nirvanko: This ain't new, see http://www.adamgotterer.com/2009/01/26/hacking-the-svn-direc...
SynteZ: IIS doesn't have this vulnerability :-) By default it doesn't send files without extensions, because it doesn't know the mime type.
varyen: Funny, Wii disks from SEGA also have .svn folders, though they're empty.
crazywebdev: Now I know how http://vkontakte.ru came about.