I once worked on a website that had a "sql.asp" page where you could enter any arbitrary SQL into a textarea and submit it. The ONLY security it had was the obscurity of its URL.
This was implemented deliberately and with full knowledge of managers and developers.
Comments
I once worked on a website that had a "sql.asp" page where you could enter any arbitrary SQL into a textarea and submit it. The ONLY security it had was the obscurity of its URL.
This was implemented deliberately and with full knowledge of managers and developers.
Stuff like this happens....