<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/16912" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2009-05-28T16:50:13-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/16912</id>

		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2009-05-28T09:43:35-04:00</updated>

		<published>2009-05-28T09:43:35-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=88987#p88987</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=88987#p88987"/>
		<title type="html"><![CDATA[Security review]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=88987#p88987"><![CDATA[
A first comment, none of the commands are safe in the concept that there is no password verification of any user. If you make a slight typo or mistake when adding new hostmasks, or let people use the ident-command from shared IP-pools, this could very well grant one malicious user access to sensitive commands.<br><br>Other than that, your code looks ok at a first glance.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Thu May 28, 2009 9:43 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Nathema]]></name></author>
		<updated>2009-05-28T16:50:13-04:00</updated>

		<published>2009-05-28T03:58:32-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=88980#p88980</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=88980#p88980"/>
		<title type="html"><![CDATA[Security review]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=88980#p88980"><![CDATA[
I decided this week to write my own public commands script. Now i know there are security issues involved.<br>Before the script got too bulky i want to have the security done good.<br><br>Can some of u review the security in my script?<br><br>EDIT: My script went public. See here: <a href="http://forum.egghelp.org/viewtopic.php?t=16913" class="postlink">http://forum.egghelp.org/viewtopic.php?t=16913</a><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10653">Nathema</a> — Thu May 28, 2009 3:58 am</p><hr />
]]></content>
	</entry>
	</feed>
