Developers Who Mean Well
[Moozik: The Lightning Seeds - Sense]
I was having a poke around the forums for the Coppermine photo gallery app (don't ask). Anyhoo, I stumbled across the announcement of a new security release here. The interesting quote, for me, was this (emphasis mine):
So far there have been no reports of an exploit of the vulnerability, so the Coppermine dev team decided not to post instructions for a manual fix to prevent wannabe-hackers from getting an idea how to create an exploit. This will of course not prevent a determined, skilled person to come up with a hack, so you better upgrade now.Wow, that sure foiled those crafty hackers didn't it? Because no one will think of downloading the new version of the php script and running a diff between it and the old version to give them the one line of code that actually changed.
Ahem.