this post was submitted on 24 Jan 2024
390 points (98.5% liked)
Cybersecurity - Memes
2015 readers
1 users here now
Only the hottest memes in Cybersecurity
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
How to say you're vulnerable to code injection without saying you're vulnerable to code injection.
Are they vulnerable though, if they already exclude it at the user input?
I yet have to learn SQL and is there a way to allow passwords with '); DROP TABLE... without being vulnerable to an injection?
nevermind i googled it, and there various ways to do so
No one in their right mind is storing plain text passwords, or letting them anywhere near the database.
You convert the password to a hash, and store that. And the hash will look nothing like the password the user typed.
Lol. Yes, people do still build systems and store plain text passwords. I regularly get scammers sending me my throwaway passwords from crappy sites. Good thing I never reuse passwords, or email addresses.