The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
safe SQL Injection query
How do i know my site is safe from SQL Injection?
|
#2
|
|||
|
|||
Good Question!
|
#3
|
||||
|
||||
How can I know that I'm safe from meteroids falling from the sky and hitting my head?
> If they do, you will know |
#4
|
|||
|
|||
Good answer
|
#5
|
|||
|
|||
Please reply someone
|
#6
|
|||
|
|||
You probably can't know for sure. If you didn't write the software or inspect the code yourself then you're trusting the people who developed the software. I guess there have been issues in vbulletin itself, but I think if you have the latest version of vb you're probably pretty safe. But I think the more mods you have installed, the greater your chance that one of them has a flaw that hasn't been found yet.
What you might be able to do to detect it is look over web logs periodically and see if you see anything strange going on. There's also a add-on called zbblock that attempts to detect and block some sql injection, but I used it for a while and found that it also blocked some users who were just doing searches (although it was a year ago so it's possible that the issue has been fixed). |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|