note 24656 deleted from function.md5 by jmcastagnetto
| From: | jmcastagnetto@php.net | Date: | Sun, 25 Aug 2002 04:50:52 +0000 |
| Subject: | note 24656 deleted from function.md5 by jmcastagnetto | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-35569@lists.php.net to get a copy of this message | ||
don't matter what you do, someone has to type their
normal password in anyway, & passwords usually
means a database exists...
Plonk your temp md5 on the database, cookies & sessions
in place of the password... you can also md5 an md5.
But what's going to stop anyone from opening your
database with a simple line for example....
<!--
mysql_connect(username)
SELECT everything
especially passwords
LIMIT none
-->
I bet it's on every one of your pages...
including your database password if it needs one
-- & I bet it don't.
Of course.... I'm all ears... Brian