PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Poll
What version of PHP-Nuke would you use if you were starting all over?
6.9
18%
 18%  [ 2 ]
7.0
0%
 0%  [ 0 ]
7.4
18%
 18%  [ 2 ]
7.5
9%
 9%  [ 1 ]
7.6
36%
 36%  [ 4 ]
7.7
18%
 18%  [ 2 ]
7.8
0%
 0%  [ 0 ]
Total Votes : 11


Author Message
64bitguy
The Mouse Is Extension Of Arm


Joined: Mar 06, 2004
Posts: 1156
Location: Sanbornton, NH USA

PostPosted: Sun Jun 19, 2005 11:03 am Reply with quote Back to top

Benson, have you added in scan, validation and filter fucntions to Nuke so that the editor:

A) Can't inject harmful SQL into the database
B) Can't inject harmful SQL into the database even when encoded
C) Can't execute an unauthorized action

If not, this is just as bad as having TinyMCE with 7.7 and 7.8.

There is no "Quick Fix" for a Nuke Platform. The platform was NEVER designed for any WYSIWYG Editor. Quite frankly, it is not quite ready for as, NUKE NEEDS A VALIDATION FUNCTION CREATED FOR ANY EDITOR!

Without validation functions, adding any editor is simply like taking a bath with a plugged-in toaster.

NOT a good idea.

Do a google search by any of these editors with the word validation after it and you will see 1000 examples of bug reports (mostly security vulnerability reports) about people whom have used them without validation, being hacked.
View user's profile Send private message Visit poster's website
benson
Worker
Worker


Joined: May 15, 2004
Posts: 119
Location: Germany

PostPosted: Thu Jun 23, 2005 12:23 am Reply with quote Back to top

Hi 64bitguy,

there is one thing left I do not understand.

What is the difference if I key those 'hacking' code into a plain textarea or into a WYSIWYG editor ?
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum