Re: Re: PHP 4.3.3RC3 Released
| From: | moshe doron | Date: | Thu, 14 Aug 2003 09:18:27 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3910@lists.php.net to get a copy of this message | ||
"Marc Boeren" <M.Boeren@guidance.nl> wrote in message
news:7BE0F4A5D7AED2119B7500A0C94C58AC3D6CCC@DELLSERVER...
>
> > that's the point. if the cracker can change only the end of
> > the query, it's not so usefull for him (he can maximum get other id)
>
> How about a form of dos:
>
> '...where id = '.$id
>
> with $id = '23129 or 1'
>
> this will select all entries in the table which could result in DoS...
>
> So, ultimately this problem is the coders responsibility.
>
DoS are not equivalent to droping the whole database (in the fast and soft
case...).
most of the system allowing searches, can be DoSed easily.
moshe