Hello moshe,

Thursday, August 14, 2003, 10:41:16 AM, you wrote:


md> "Derick Rethans" <[EMAIL PROTECTED]> wrote in message
md> news:[EMAIL PROTECTED]
>> On Thu, 14 Aug 2003, moshe doron wrote:
>>
>> > What about hacking somehow the sqlite library to disallow chained
md> queries
>> > (or at least do it optionally)?
>> >
>> > This behavior is *huge* security hole, allow to the cracker drop ur
md> database
>> > using simple select where query.
>>
>> How is this a security hole?

md> http://www.phpbuilder.com/mail/php-developer-list/2003022/0062.php

Bullshit.

If the cracker can change one of your sql statements he already has access to
your machine. In that case he wouldn't bother changing your sql statements.




-- 
Best regards,
 Marcus                            mailto:[EMAIL PROTECTED]


-- 
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to