Mittwoch, 23. Februar 2011

Ever thought about indirect web attacks?

(Date/Datum: 080218-00:55, Hits: 1349) I work since more than one year on the development of a huge commercial website (LAMP) with lot of functionality. Today I developed a communication system which can be used to contact other users, view messages already sent, delete messages and the like (these tasks aren't finished @the moment).

Did you ever thought about the scripts such a big site runs in the background? For example a script that deletes all users messages older than 4 weeks or so to keep the message database small and clean? Such scripts exist and it is maybe very hard to attack them -- and of course: you can only do it indirect -- but this should be possibly.

