Re: Re: PHP 4.3.3RC3 Released
| From: | (Marcus B�rger) | Date: | Thu, 14 Aug 2003 07:50:35 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3903@lists.php.net to get a copy of this message | ||
Hello moshe,
Thursday, August 14, 2003, 10:41:16 AM, you wrote:
md> "Derick Rethans" <derick@php.net> wrote in message
md> news:Pine.LNX.4.53.0308140932320.12247@jdi.jdimedia.nl...
>> On Thu, 14 Aug 2003, moshe doron wrote:
>>
>> > What about hacking somehow the sqlite library to disallow chained
md> queries
>> > (or at least do it optionally)?
>> >
>> > This behavior is *huge* security hole, allow to the cracker drop ur
md> database
>> > using simple select where query.
>>
>> How is this a security hole?
md> http://www.phpbuilder.com/mail/php-developer-list/2003022/0062.php{7š–¼mlã
md> çº&«œ
Bullshit.
If the cracker can change one of your sql statements he already has access to
your machine. In that case he wouldn't bother changing your sql statements.
--
Best regards,
Marcus mailto:helly@php.net