Quote:
Originally Posted by AWS
While I have trust in the authors of the hacks here it would be very easy for one of them to put in a backdoor that would give them control of your forum or your whole server.
|
This is true. I think maybe we should create some sort of "verified" system. When we upload attachments, they are marked as unverified (but still downloadable). Then maybe have a team that goes around and checks newly uploaded or updated attachments for unsafe code. Once it's passed the check, display a "verified" badge on the attachment.