libssh: Authentication bypass in server code.

– CVE-2018-10933
– affected are libssh 0.6 and above
– attackers can authenticate without proving any credentials
– update to libssh 0.8.4 / 0.7.6

when I first ran D&D, my grandmother, who had bought fully into the IT'S SATANISM hype, insisted on sitting and watching the first session

about an hour in, she threw her hands up and yelled 'THIS IS JUST MATH' and stormed off

Documentation: "Use the crypt() function to encode passwords for additional users in the config.php file."

Found in config.php:
$user['admin'] = crypt('plaintextpasswd');

Yeah ... um ...

