// archives

Archive for October, 2007

Preventing URL Injection Attacks

Although I was supremely irritated that someone was hacking intermz and uploading malicious files (i.e. eBay phishing files, etc) to the server, I have to give those hackers credit for the effectiveness and simplicity of their hack, what I will call a “URL injection” attack. (This differs from a SQL injection attack, which is another [...]