Full Disclosure mailing list archives

Re: Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature


From: Jasper Bryant-Greene <jasper () album co nz>
Date: Sun, 02 Apr 2006 18:47:55 +1200

Siegfried wrote:
Yes like you said there is no check, because the stripslashes is a joke.
And yes this script isn't famous at all, but it was just to show a recent
example of an error in the advisory, even if this one is just a detail

Stripslashes is not a joke, it's just not designed for what its being used for. The developer that tries to use it for input validation/checking, now *there's* the joke!

--
Jasper Bryant-Greene
General Manager
Album Limited

http://www.album.co.nz/     0800 4 ALBUM
jasper () album co nz          021 708 334

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: