Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The exploit was not anything to do with PHP. A section of their site was allowing to users to execute commands under a user which they should not have been allowed to. This could have happened under any programming language.


Especially given that their codebase is apparently Ruby and not PHP.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: