11
linuxxx
7y

They used strcmp (PHP) on the main server as only form of authentication...

Comments
  • 1
    Oh that's horrible :( Did they at least made sure the input was a string before comparing? I can imagine people POSTing other data types and getting in due to the nature of strcmp
Add Comment