Can someone explain to me the point of placing a possible path to the password file in the "new username" (
call, which seems highly unlikely? In fact, I'd only see a point in attempting a SQL injection attack at this point (any users named
out there?)
I think you'd be a fool to think that the [id://pmdev]s on PerlMonks left any obvious security holes. That's not to say there's never been a