Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Other - Discussion
Poll
What version of PHP-Nuke would you use if you were starting all over?
6.9
18%
 18%  [ 2 ]
7.0
0%
 0%  [ 0 ]
7.4
18%
 18%  [ 2 ]
7.5
9%
 9%  [ 1 ]
7.6
36%
 36%  [ 4 ]
7.7
18%
 18%  [ 2 ]
7.8
0%
 0%  [ 0 ]
Total Votes : 11


Author Message
64bitguy
The Mouse Is Extension Of Arm



Joined: Mar 06, 2004
Posts: 1164

PostPosted: Sun Jun 19, 2005 11:03 am Reply with quote

Benson, have you added in scan, validation and filter fucntions to Nuke so that the editor:

A) Can't inject harmful SQL into the database
B) Can't inject harmful SQL into the database even when encoded
C) Can't execute an unauthorized action

If not, this is just as bad as having TinyMCE with 7.7 and 7.8.

There is no "Quick Fix" for a Nuke Platform. The platform was NEVER designed for any WYSIWYG Editor. Quite frankly, it is not quite ready for as, NUKE NEEDS A VALIDATION FUNCTION CREATED FOR ANY EDITOR!

Without validation functions, adding any editor is simply like taking a bath with a plugged-in toaster.

NOT a good idea.

Do a google search by any of these editors with the word validation after it and you will see 1000 examples of bug reports (mostly security vulnerability reports) about people whom have used them without validation, being hacked.

_________________
Steph Benoit
100% Section 508 and W3C HTML5 and CSS Compliant (Truly) Code, because I love compliance. 
View user's profile Send private message
benson
Worker
Worker



Joined: May 15, 2004
Posts: 119
Location: Germany

PostPosted: Thu Jun 23, 2005 12:23 am Reply with quote

Hi 64bitguy,

there is one thing left I do not understand.

What is the difference if I key those 'hacking' code into a plain textarea or into a WYSIWYG editor ?

_________________
Best regards, Norbert

gebiet51.de & fellpartner.de 
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Other - Discussion

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©