Tag: infosec

  • Double-negative auth: a vulnerability story

    In university I ran a Drupal website for an undergraduate student body. The university had a single-sign-on system called “Raven”, and happily someone had already had written a Drupal 5 module to allow using Raven authentication, called “ucamraven“. When Drupal 6 came out, I dutifully wrote a Drupal 6 version of ucamraven but got stuck…