Re: ODBC_EXECUTE has a DANGEROUS 'feature'!!!
| From: | * R&zE: | Date: | Mon, 11 Feb 2002 14:54:41 +0000 |
| Subject: | Re: ODBC_EXECUTE has a DANGEROUS 'feature'!!! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-84279@lists.php.net to get a copy of this message | ||
> I think you all are missing the point that *R&zE is making.
>
> The software you use/create should be bugfree and free from undocumented
> features. Otherwise security risks could occur. And ofcourse all other
> safe-guard (like checking input, correct rights on the FileSystem) should be
> placed too.
>
> It is bugs like these who create life for Hackers and viruses (like nimda).
> Of course you can say that is the users own fault. But it is the developers
> duty to inform and advise users, and not to look the other way in the hope
> that it goes away.
>
> Jerry
Absolutely true!
I don't really care that this 'feature' exists (although it's not a
smart thing to do, if someone wants to put the contents of a file in
the database, let 'm write it himself) but it should have been
documented.
If it was to be found somewhere in the documentation I would have
made a check on this. But it can't be found anywhere. So then
there's nothing to check.
--
* R&zE: