Serious question: if an attacker has the necessary access to modify the data in the table (because that is what it would take to cause a problem) or if someone installs a malicious module do I really have any way to stop it?
On 19 Jun 2006, at 18:41, Earl Dunovant wrote:
> These fields are coming from the database, and the table is
> populated with data from Amazon.com. I prefer scrubbing it on the
> way in (admittedly not doing that at the moment because I figured
> if you can hijack Amazon.com's servers you're going to get me if
> you want to anyway). The fewer places I have to worry about it, the
> better.
That doesn't work. People (or modules) could edit or modify the node
at any time, and then you'd be toast. :-)
--
Dries Buytaert :: http://www.buytaert.net/