Product Security
Saturday, March 22nd, 2008In the past couple of weeks the Mihalism development team has been receiving emails regarding the security behind our products. This is the official response to our security wellness.
We have been receiving these emails because of security holes in old versions of our products that people have found and posted on the internet. Once these holes are posted, other sites pick up on them, and as a result there are tens to hundreds of sites listing these vulnerabilities. The worst part of this is when Google finds these pages and lists them as top search results for terms such as “Mihalism Multi Host”, “Mihalism”, etc.
First, let us leave a general disclaimer that nothing is “hack-proof”. The good hackers out there are extremely crafty fellows. I mean, you hear about government agencies and banking firms getting hacked, so you can imagine virtually anything is possible.
Whenever a security issue is reported, our staff work hard to determine the issue and area of code concerned, develop a patch that will correct the problem, test the patch, and deliver it to customers as quickly as possible. When a security patch is available all products containing the vulnerability will be updated and an announcement will be posted informing everyone of the cause and information on how to fix it.
Security patches will always be necessary by any vendor. It’s a fact of life, and you will notice virtually every software vendor has to deliver them. However we do strive to limit our exposure and to deliver patches as quickly as possible when they become necessary.
As of the time this was posted, all our products are using the most advanced security measures available to prevent SQL injection and any other type of hack. If you do discover a hack, do not be bad and exploit it, report it as soon as possible to hackercheck@mihalism.com.