logoalt Hacker News

mikestewyesterday at 12:57 AM2 repliesview on HN

Well, I had to call it something. File system DBs were a problem long before FoxPro’s DBCs, yes. Yes, it’s an architectural decision. Sharp cookies would just modify the files directly. But that would just trash data (or bump my hourly rate in the HR DB). Most of the time, “full access to data” doesn’t necessarily mean “run arbitrary code”. In this case, it does, which I don’t think folks expect, hence “hole”.


Replies

Shorelyesterday at 11:53 AM

There's a category in the OWASP Top 6, called: Insecure Design.

It is top 6 in their vulnerabilities ranking.

This is definitely insecure design.

dspillettyesterday at 1:22 AM

> Well, I had to call it something.

A significant weakness?

A serious limitation for modern uses / in modern environments?

show 1 reply