Fr3DBr Posted August 22, 2016 Share Posted August 22, 2016 Hi, guys. Is the login API from whmcs, safe to use without sanity checking on user supplied strings ? 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted August 23, 2016 Share Posted August 23, 2016 it should be 0 Quote Link to comment Share on other sites More sharing options...
Fr3DBr Posted August 23, 2016 Author Share Posted August 23, 2016 it should be The "should" in the sentence is what makes me afraid haha. 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted August 23, 2016 Share Posted August 23, 2016 your question has no guaranteed answer why don't you try to inject it and see what happens 0 Quote Link to comment Share on other sites More sharing options...
Fr3DBr Posted August 23, 2016 Author Share Posted August 23, 2016 your question has no guaranteed answer why don't you try to inject it and see what happens I would like to get a reply from whmcs staff, as their documentation doesn't says anything about it anyways. 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted August 23, 2016 Share Posted August 23, 2016 I would like to get a reply from whmcs staff, as their documentation doesn't says anything about it anyways. you need to contact them directly, I hope they will not redirect you back to the forum 0 Quote Link to comment Share on other sites More sharing options...
WHMCS ChrisD Posted August 23, 2016 Share Posted August 23, 2016 Hello Fr3DBr, Whilst yes the login API is safe to use without sanity checking we do not recommending this and encourage you to always sanitise information. 0 Quote Link to comment Share on other sites More sharing options...
Fr3DBr Posted August 23, 2016 Author Share Posted August 23, 2016 Hello Fr3DBr, Whilst yes the login API is safe to use without sanity checking we do not recommending this and encourage you to always sanitise information. We do this, although since it interfere a bit with the login procedure, I'd like to know if we can only do not do this when using the Login API, get it ? Everything else is sanitised. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.