Web Hosting Talk







View Full Version : what's this about the new php 4.1.2 reporting usage back to author?


skylab
03-04-2002, 12:48 AM
or am i messed up?

i just got this from the cobalt security mailing list, but nothing previous. so, i'm a bit in the dark.


__________________________________________
Today's Topics:

1. Re: Unofficial PHP 4.1.2 PKG available (cbtrussell)

--__--__--

Message: 1
From: "________" <_______@hotmail.com>
To: <cobalt-security@list.cobalt.com>
Subject: Re: [cobalt-security] Unofficial PHP 4.1.2 PKG available
Date: Sun, 3 Mar 2002 19:58:24 -0500
Reply-To: cobalt-security@list.cobalt.com

> well, if this is detailed information or not is to be argued about. But
> well, yes. It is phoning home so that I'm able to track the spreading of
> the package.

Busted.

> And now tell me which information in
> this e-mail is sensitive to your privacy?!

I would be very upset if I installed a piece of software that sent the
author the address of my machine, as well the kernel info enclosed below. I
think it's sneaky and ill-advised at BEST. The worst part is your failure
to disclose the spyware prior to being caught red-handed, which speaks
volumes about your ethics. Is there a sinister motive here? I honestly doubt
it, but even so, you can bet I won't ever be installing any pkg's from your
site.

ukwebhost
03-04-2002, 10:19 AM
This does look quite sinister, it is possible to do it aswell. I recommend that you only install software direct from Cobalt's or PHP's website.
Why don't people install the latest PHP version given by PHP? Is there an incompatibility with the Cobalt system, or is it just lazyness?


Thanks.

:D

kmurrey
03-04-2002, 10:24 AM
No, cobalt allows you to point to a .pkg file and install it. It's very simple to do.

You do it from the GUI. I don't think it's laziness... I think that it is more convenient.


__________________
Keith

NoComment
03-04-2002, 11:58 PM
CObalt will not support your hardware if you use anything but Official Cobalt packages. (pkg.nl.cobalt.com ..now pkgmaster.com is *NOT* official but is AWESOME)