Support A2Billing :

provided by Star2Billing S.L.

Support A2Billing :
It is currently Tue Apr 23, 2024 4:08 pm
Predictive Dialer


All times are UTC




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: The format of $server_GMT Or: data sanitization
PostPosted: Fri Dec 10, 2010 7:08 pm 
Offline

Joined: Thu Jun 05, 2008 5:35 pm
Posts: 37
We just started using A2Billing v1.8.1 and I was trying to figure out what format A2Billing actually uses for the definition of $server_GMT, when I realized that it was accepting *any* value in *any* format.

This of course, was not helpful. Neither was any discussion in this forum.

And I couldn't help but notice that when a program accepts a value in any format like that, that there's no data sanitization in that program. And it really makes me wonder whether or not I want to use this billing system, which has its own little customer signup form that's publicly available on the internet for just anyone to sign on as Little Bobby Tables...

Image

But of course, my actual question was "What's the format of $server_GMT?"


Top
 Profile  
 
 Post subject: Re: The format of $server_GMT Or: data sanitization
PostPosted: Mon Dec 13, 2010 12:52 pm 
Offline
Moderator
User avatar

Joined: Thu Jun 22, 2006 2:19 pm
Posts: 2890
Location: Devon, UK
gromm wrote:
But of course, my actual question was "What's the format of $server_GMT?"
A quick check of the code indicates it must match one of the entries in the cc_timezone table.
Quote:
And it really makes me wonder whether or not I want to use this billing system, which has its own little customer signup form that's publicly available on the internet for just anyone to sign on as Little Bobby Tables...
I too would like to see pervasive use of parameterised queries, which would make injection attacks impossible. It's a big job to retrofit them though. :(


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 
VoIP Billing solution


All times are UTC


Who is online

Users browsing this forum: No registered users and 31 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group