TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: Antti Kurenniemi
from: Adam Flinton
date: 2004-03-22 22:57:04
subject: Re: exploits

From: Adam Flinton 

Antti Kurenniemi wrote:

> I wouldn't blame those on PHP (though it certainly makes it very easy to
> write unsafe code), but more on lazy / incompetent developers / testers. I
> think it doesn't really depend on what language you use, if you do database
> stuff that has any user input you simply must validate all input before
> proceeding, in each and every step.
>
>

Yup. I've seen SQl injection attacks against SQl Server behind IIS.

Adam

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270
@PATH: 379/45 1 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.