|
Web Application Security
Fwd: PHP Easter Eggs Nov 28 2004 01:21PM Andi McLean (andi_mclean ntlworld com) (6 replies) Re: PHP Easter Eggs Nov 30 2004 04:12AM Serban Gh. Ghita (serban verasys ro) (2 replies) Re: Fwd: PHP Easter Eggs Nov 29 2004 04:17PM Saqib N Ali seagate com (2 replies) Re: Fwd: PHP Easter Eggs Nov 30 2004 08:53AM exon (exon home se) (2 replies) Re: PHP Easter Eggs Nov 30 2004 06:24PM Paul Fierro (pablo nothing com) (1 replies) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) Re: PHP Easter Eggs Nov 30 2004 06:24PM Paul Fierro (pablo nothing com) (3 replies) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) Re: Fwd: PHP Easter Eggs Nov 30 2004 08:53AM exon (exon home se) (2 replies) Re: PHP Easter Eggs Nov 30 2004 06:24PM Paul Fierro (pablo nothing com) (1 replies) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) Re: PHP Easter Eggs Nov 30 2004 06:24PM Paul Fierro (pablo nothing com) (3 replies) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) |
|
|
Privacy Statement |
gems" in there in the first place. Since no one else seems to want to
come right out and say it, I'll do it. If that's in there, what else
is in there that we just haven't found yet?
A photograph of someone's dog in and of itself isn't very threatening.
However, when you expect your system and and application to be fairly
secure and you find something like this, you have to wonder what else
is there that's also not "public".
Does this mean that if I go join up on the PHP developers mailing
lists/forums that I can find out about other stuff that might enable
me to compromise a widely used e-commerce application like osCommerce?
or nukeCommerce? or phpShop? or X-cart? or any of the other scads of
both commercial and opensource e-commerce suites that are available.
The only comment I have for the PHP development team is that this is
_VERY_ uncool.
2 cents,
Jimi
On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:
> On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:
>
> > The code should be removed from PHP altogether since it doesn't exactly
> > provide much in the way of functionality. Possibly php_credits() could
> > be added as a function, the way php_info() is now. That way nobody could
> > glean information unawares, but the info would still be there if you
> > need it (and it would be much easier to come by).
>
> A function named phpcredits() already exists:
>
> http://www.php.net/phpcredits
>
> Paul
>
>
--
Thanks,
Jimi
[ reply ]