390
you are viewing a single comment's thread
view the rest of the comments
[-] ArbitraryValue@sh.itjust.works 178 points 11 months ago

How to say you're vulnerable to code injection without saying you're vulnerable to code injection.

[-] tryptaminev@feddit.de 30 points 11 months ago* (last edited 11 months ago)

Are they vulnerable though, if they already exclude it at the user input?

I yet have to learn SQL and is there a way to allow passwords with '); DROP TABLE... without being vulnerable to an injection?

nevermind i googled it, and there various ways to do so

[-] herrvogel@lemmy.world 51 points 11 months ago

This still smells though. Why is the raw, plain text password string getting anywhere near database queries in the first place?

[-] cactusupyourbutt@lemmy.world 19 points 11 months ago

I doubt it is. they probably have a WAF that blocks these strings though and didnt want to bother reconfiguring it

load more comments (11 replies)
load more comments (15 replies)
this post was submitted on 24 Jan 2024
390 points (98.5% liked)

Cybersecurity - Memes

1893 readers
2 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS