Yeah I was thinking the same too but as said before I said potential for a reason. There *might* be a way of getting around the hash and executing a rogue query. We simply do not know. But it's better to be safe than sorry right? Like. If filtering is not going to change anything you may as well do it ? :)
This is not exploitable, as the value returned is a hash, and nothing more. You can not inject anything within the query as the value returned by uberHash will only be letters and numbers.
/facepalm
I also use an uberCMS edit. However i've had my cms fully secured for a while now. That won't be an exploit in a password field cause it's hashed and it's not counted as real input? I'm not sure how it's processed.
Thanks though.
Jontycat
'k. You're 3 posts late. This has been said already. Understand I'm a novice programmer (I've only being doing this a few months and im learning still) and that I'm not stupid. The mark 'Potential' in the title means I'm not sure if it is. I released something which *could* have been very beneficial to the community. Some one else could've found this out before me and gone around exploiting hotels have this not been a hash.
So, whilst the release its self as not useful. The thought of releasing a fix to release a *maybe* exploit is, imho.
Also, you was once like me in terms of knowledge of programming so ending your post with "/facepalm" is hypercritical of you as you once make mistakes and didn't take things into account your self.
So shut the fuck up, all of you. I'm now aware and I was after Kyrptos' post
Calm down, I wasn't being aggressive I was simply stating. If you read my posts it's pretty much sounding like I was trying to explain it to myself while asking a question to those around us who are better. You're being a tool, not me.
Also, haven't you been going around acting like you're an amazing programmer, posting on developments like you know something, but now, you're calling yourself a novice? Steep drop. Professional to novice.
Not having a go at you - good release, thanks for sharing it with the community as the retro community is dying, so we all need to start contributing or shit's gonna go down, fast.
Thanks & good luck with future learning.
Jonty, it wasn't aimed at you. I never claimed to be a professional. I could probably write a hole CMS if I really wanted to. I have an understanding of most things. But I couldn't write forum software like.. vBulletin. So, I'm kind of inbetween. I didn't know what to name my self so I thought novice might be the best one. Considering It's only been a few months, ya know? Or maybe a better word would be like.. 'standard'? I'm not sure now to measure coding knowledge.
Last edited by Matthew; 18-07-11 at 07:08 AM.