in reply to how could i make "them" understand that security IS important ?
Under perl, -T will get you very far with answering these questions too.
I have to repeat what others have said here, you can not trust the client, even if it isn't just a browser, but something closed source and compiled. It is not exactly hard (usually) to capture whatever the client is sending and mimic/"enhance" that yourself. If you aer worried about extra parameters doing any harm, filter server-side! Always! Anything client-side is just cosmetics. :)
This also reminded me about this node by merlyn. Is a good laugh about undoubtedly real security flaws. :)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: how could i make "them" understand that security IS important ?
by iza (Monk) on Sep 12, 2002 at 09:08 UTC |