If they don't cleanse the input to a database, they deserve what they get.

I swear. I'm tempted to name my kid ' or 1=1;drop users



Cody Robertson wrote:
> Is it a SQL injection / xss? Please send me information regarding this  
> thanks. I'm personally not aware of any other communities for hlstatsx.
> 
> - Cody Robertson
> 
> On Jun 21, 2008, at 9:12 AM, "Keeper" <[EMAIL PROTECTED]> wrote:
> 
>> I know this is not a source game issue, but since it is written for  
>> and used
>> by source game operators I wanted to ask here:
>>
>> Is there no longer any community based support for HLStatsX?  I  
>> noticed Tobi
>> has removed the forums from his site.  Somebody has pointed out a  
>> serious
>> security flaw to me that we fixed.  If it isn't rolled out into the  
>> free
>> downloaded version I wanted to make the fix public.
>>
>> I will of course post it here, but wanted to know if there was  
>> anywhere else
>> off-list that I could inform users of HLStasX.  Thankfully it's an  
>> easy fix.
>>
>> We have found a security hole, but to our knowledge it hasn't been  
>> exploited
>> yet at any of the servers that we have checked out.
>>
>> Thanks,
>> Keeper
>>
>>
>> _______________________________________________
>> To unsubscribe, edit your list preferences, or view the list  
>> archives, please visit:
>> http://list.valvesoftware.com/mailman/listinfo/hlds
> 
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives, please 
> visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds
> 
> 

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds

Reply via email to