Re: Potentially Dangerous URL

Jan Schneider <[email protected]> Wed, 26 Oct 2005 00:04:21 +0200
Newsgroups gmane.comp.horde.chora
Message-ID <[email protected]>
Zitat von Admin <[email protected]>:

>
> Jan,
> would you be so kind to explain me how I could hack the code?

Take a look at services/go.php.

>> Date: Tue, 25 Oct 2005 09:29:01 +0200
>> From: Jan Schneider <[email protected]>
>> Subject: Re: [chora] Potentially Dangerous URL
>> To: [email protected]
>> Message-ID: <[email protected]>
>> Content-Type: text/plain;    charset=ISO-8859-15;    format="flowed"
>>
>> Zitat von Admin <[email protected]>:
>>
>>
>>
>>> Therefore I think is should be an user option, if not an admin
>>> option, to disable this so called "security feature", at admin's
>>> risk, if you want to say so.
>>>
>>>
>>
>> No. Hack the code if you don't want to bother your users with extra
>> security. *We* care about web application security.
>>
>> Jan.
>>
>> --
>> Do you need professional PHP or Horde consulting?
>> http://horde.org/consulting/
>>
>>
>>
>> ------------------------------
>>
>>
>> --
>> Chora mailing list
>> Frequently Asked Questions: http://horde.org/faq/
>> To unsubscribe, mail: [email protected]
>>
>>
>> End of chora Digest, Vol 350, Issue 1
>> *************************************
>>
>>
>>
>>
>
>
> --
> Chora mailing list - Join the hunt: http://horde.org/bounties/#chora
> Frequently Asked Questions: http://horde.org/faq/
> To unsubscribe, mail: [email protected]
>
>



Jan.

-- 
Do you need professional PHP or Horde consulting?
http://horde.org/consulting/

-- 
Chora mailing list - Join the hunt: http://horde.org/bounties/#chora
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: [email protected]