Re: Re: Mommy, is it true that...?
| From: | Bogdan Stancescu | Date: | Fri, 21 Dec 2001 02:26:13 +0000 |
| Subject: | Re: Re: Mommy, is it true that...? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-78391@lists.php.net to get a copy of this message | ||
Philip Hallstrom wrote:
> > A definite possibility, but it does depend on the hacker in question
> > knowing exactly how your script is written...
>
> True, but in a shared hosting environment this is very likely.
...not to mention open source code. However, the discussion was indeed oriented
towards MySQL. Hoever (again), the exec() argument is indeed something worth
mentioning - I now realize there may be some serious security holes in an open-source
project I'm currently woking on (ouch!)
Bogdan