Quote:
Originally Posted by Lynne
Automated modification security? I can't even imagine writing the script to do that. Besides that, we like mods to be uploaded as zip files so all the files are together in one place.
And, as Joe stated, we've had one plugin lately that had a security problem. The last time we had something quarantined for a security reason was last June.
|
Modification security could just unzip the attachment, analyze every line and check if they're SQL statements are escaped properly.
According to the
vb.com thread about the latest SQL injection issues, a ton of plugins are currently susceptible, but no one really knows until they get hacked. A few plugins that were confirmed to be insecure (some got fixed) were "Advanced Rules" and "Admin Log In As User".