in reply to How safe is my perl cgi website?
Asking others to find security problems for you by hacking into your site -- a site that you already brought to its knees once with security problems, and a site that you already know currently still has at least a couple -- is a bad idea.
Telling us there exist problems, and suggesting we might find them if we try is just asking for more trouble than you can deal with.
But even more important than that, you seem to believe that security exists through obscurity. That is to say, if the security problem is not announced, it must therefore be pretty secure. It's not. Though the dozen or so people who read your post with enough ambition to actually look at the site may or may not find the issue after casual looking, that doesn't tell you anything about what the 300 million other people on the Internet may be able to find.
Security isn't a matter of being lucky enough that people don't find the flaw. It's a matter of taking care to prevent flaws from being accessible.
Dave
|
---|