[TYPO3-dev] config.baseURL, lt_basetag and security

Marc Wöhlken woehlken at quadracom.de
Wed Sep 23 17:24:07 CEST 2009


Hi!
Ries van Twisk schrieb:
> I am not sure how the spoofing actually works, but from the looks of it
> this extension could introduce the exact same problem.
Bad extension coding style like using $_SERVER[HTTP_HOST] instead of
$_SERVER["HTTP_HOST"] does not give me a warm and fuzzy feeling, too.

	Marc

-- 
...........................................................
Marc Wöhlken                     TYPO3 certified intregator

Quadracom - Proffe & Wöhlken

Rembertistraße 32              WWW: http://www.quadracom.de
D-28203 Bremen                E-Mail: woehlken at quadracom.de
______________             PGP-Key: http://pgp.quadracom.de




More information about the TYPO3-dev mailing list