hi!,
I saw in default HTML in Posts Disabled...Why is that? Is there any security reason or anything???
Why HTML Desable?
Subject: Re: Why HTML Desable?
Yes basically a someone could run a script when posting a message that could gain access to your database or your php files...
I have no idea what they could do as I have no experience if ruining anyone sites but thats the general impression of what could happen..
:mrgreen: :mrgreen:
I have no idea what they could do as I have no experience if ruining anyone sites but thats the general impression of what could happen..
:mrgreen: :mrgreen:
Subject: Re: Why HTML Desable?
Yep, security.
They can take your user and pass, insert iframes vith viruses, spyware, keyloggers..... if it is disabled.
DWho, it is less problably they take php files or touch the DB with HTML code as HTML is client side, but if PHP is injected.... they can even crush both client and server
They can take your user and pass, insert iframes vith viruses, spyware, keyloggers..... if it is disabled.
DWho, it is less problably they take php files or touch the DB with HTML code as HTML is client side, but if PHP is injected.... they can even crush both client and server
Page 1 of 1
You cannot post new topicsYou cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events
This is a "Lo-Fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Powered by Icy Phoenix based on phpBB
Generation Time: 0.0322s (PHP: 47% SQL: 53%)
SQL queries: 10 - Debug Off - GZIP Enabled