Re: Re: PHP 4.3.3RC3 Released
| From: | moshe doron | Date: | Thu, 14 Aug 2003 08:59:31 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3906@lists.php.net to get a copy of this message | ||
"Marcus BöRger" <marcus.boerger@t-online.de> wrote in message
> md>
> md> http://www.phpbuilder.com/mail/php-developer-list/2003022/0062.php
>
> Bullshit.
>
> If the cracker can change one of your sql statements he already has access
to
> your machine. In that case he wouldn't bother changing your sql
statements.
>
that's the point. if the cracker can change only the end of the query, it's
not so usefull for him (he can maximum get other id) but if he can chain
totally new query, he may or may no bother changing your sql statements....
moshe.