|
|
|
|
|
by uxcn
3973 days ago
|
|
my immediate thought is that they're passing raw userdata into the database as strings That was my first thought too. I'd guess that it's a vulnerability somewhere in the code for handling the forums. I would be willing to bet that they could get rid of a lot of the attack surface just by using standard services for certain things. |
|
Although judging by a screenshot of the recent hack[0] posted here[1] escaping (and XSS) may not be an issue.
[0]https://i.imgur.com/pl22srz.png
[1]https://news.ycombinator.com/item?id=9990221