in reply to "Hardening" a web forum app
Addressing "principles" first (but directing this response to your broad question on exploitation, rather than to the specific examples of potential problems): the simplest may be to use existing, well-tested OS forum s/w. Rolling your own with even a glimmer of a possibility of opening its use to other than those who "can all be trusted" is either:
Nonetheless, ++ for thinking about it....
Now, some possibly relevant procedures:
And far beyond the trivia above, lots of heavy reading about vulnerabilties and how to minimize them.
|
|---|