• gerikson@awful.systems
    link
    fedilink
    English
    arrow-up
    21
    ·
    3 days ago

    Thanks for this write-up, I just saw the advisory and didn’t realize just how dumb the entire thing was.

    • David Gerard@awful.systemsOPM
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 days ago

      absolutely appalling figuring it out, it really was “it can’t be this stupid, I must be understanding it wrong”

      then I got to the bash injection

      and the proud “Generated by Claude Code”

      and welp

      • HedyL@awful.systems
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        More than two decades ago, I dabbled a bit in PHP, MySQL etc. for hobbyist purposes. Even back then, I would have taken stronger precautions, even for some silly database on hosted webspace. Apparently, some of those techbros live in a different universe.