Use PHP to build a Twitter-like system on your site
ibm.com
ibm.com
There's also no hashing/salting of user passwords or anything. Even with some minor coding experience you should be able to pick this out.
I'm 17 years old, falling into your teen category, and there is no way I would ever run that code in a production environment - just by looking at it I can tell it's unfit.
Have a look at some of the sites here if you have time: rev.iew.me/users & you'll see what I mean.
For the record, I agree, code shouldn't have to come with a warning label; but I have seen many a site taken taken down by similarly bad code. I do my very best to help these youngsters where I can, because I was in their position once too. (Hence why I am here, to learn more and be able to offer more help to those who don't know so much.)
Well, to be specific, that was the case for me from 13 to 16, then I started prefacing that with "I'm majoring in computer science" and then the discrimination started to go away.
- http://php.net/mysql_real_escape_string "Note: If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks."
- http://www.php.net/manual/en/security.database.sql-injection...
- http://www.metatitan.com/php/16/protecting-your-phpmysql-que...
- http://en.wikibooks.org/wiki/Programming:PHP:SQL_Injection
If HTML entities works properly, and it is used properly, shouldn't it prevent XSS since an attacker who inputs something like <script>alert("xss")</script> would simply see the message displayed back to them instead of the browser actually executing it?
Second, in the time it took to write this article, one could have built the actual app to provide for download or as an open-source project.