Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless I'm missing something here, lacking parametrization is not the issue here. The issue is that it's obvious they are saving the password in plaintext instead of hashing it, otherwise the password would never get close to an SQL query to allow injection.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: