Silk Road was using PHP also. I tried some SQL injections in its earlier days (mid-2011), and got back full error reports including the mySQL commands (I never successfully exploited it because I wasn't able to get a closing parenthesis ")" past the sanitizer). They changed the server config shortly afterwards, and stopped printing the debug messages.
Comments
Silk Road was using PHP also. I tried some SQL injections in its earlier days (mid-2011), and got back full error reports including the mySQL commands (I never successfully exploited it because I wasn't able to get a closing parenthesis ")" past the sanitizer). They changed the server config shortly afterwards, and stopped printing the debug messages.