It could also be a compromise in their ftp, which would allow someone
to write whatever they please into the cfm templates. Saw that once.
Some clown put code into the very top of a template that used cffile
to store the good bits of order form input and then saved it somewhere
web-accessible.  Then they just hit the file and harvested data
onscreen.  They even took the time to add a cvv number to the site's
web order form.  Simple and thorough :-(.

--
--Matt Robertson--
MSB Designs, Inc.
mysecretbase.com
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings] [Donations and Support]

Reply via email to