Jump to content

possible to SQL Inject?


bholzer

Recommended Posts

What would it be vulnerable to?

 

Any and all valid attacks. It has absolutely no protection at all (assuming magic_quotes_gpc is off, and even that offers little to no protection).

 

It just seems to be posting any strings to the valid fields. Im trying to grasp the idea of security and injection and such. I just cant seem to do anything out of the ordinary!

You may want to read the tutorials located:

 

http://www.phpfreaks.com/tutorial/php-security

 

About PHP Security, if you are interested in it. No need for people to beat the topic to death as it has been covered (in that tutorial) and on this site many many many many many times.

(assuming magic_quotes_gpc is off, and even that offers little to no protection).

 

I'd love to know more about this. I mean how'd you bypass magic_quotes?

 

@OP

I also this you have magic_quote_gpc on. Change its value to off in php.ini and then try the attacks again.

 

 

I'd love to know more about this. I mean how'd you bypass magic_quotes?

 

@OP

I also this you have magic_quote_gpc on. Change its value to off in php.ini and then try the attacks again.

 

okay, im a total newbie, here, so im sorry, but youll have to bear with me, how do i setup php.ini, i havent set one up yet!

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.