[TYPO3-dev] Thoughts about security in BE

Dmitry Dulepov [typo3] dmitry at typo3.org
Fri Jan 18 19:22:02 CET 2008


Hi!

Marcus Krause wrote:
> If someone highjacked an admin accound via XSS, admin is someone else 
> not the person that you intended to be admin!

If someone found root password for the server..........

-- 
Dmitry Dulepov
TYPO3 core team
Web: http://typo3bloke.net/
Skype: callto:liels_bugs
"Nothing is impossible. There are only limits to our knowledge"




More information about the TYPO3-dev mailing list