3 ms·
That's fair, but my point was small code doesn't mean bug free, and just because you only use it in a certain way and don't see any bugs doesn't mean they're no
by kichimi 5y ago
That's fair, but my point was small code doesn't mean bug free, and just because you only use it in a certain way and don't see any bugs doesn't mean they're not there. In fact I'd wager there are multiple gaping issues with it, that you simply wont encounter.
If your code is as small as I'm imagining it, then it's not handling a lot of error cases, and doesn't cover any edge cases. That's where bugs lurk.
- 6510 5y agoThe components are like this: Auth is a cookie, session, ip and password check. It builds a html document from 3 strings. It writes the document to the file system and to the backup folder. Which part do you imagine to be the most error prone? I'm having a hard time imagining doing fwrite wrong. I mean? lol? For the malicious actor to gain access they would need to guess the url, guess what the post vars are called, obtain a cookie (set by a deleted php file) and guess the password. Then one would be able to edit or create a html document. I suppose inserting some malicious js into the newest post shortly after its created could escape my attention. It could take some time for me to notice it. When I do notice it ill restore the documents from a backup. It wouldn't take a DBA. My rss reader wouldn't like <script> onload onclick etc. I think I would notice my own feed getting flagged. I'm sure someone could hack the blog but its not worth the effort.