since some intrepid hackers can do a lot of evil with the proper HTML tags

..especially with a forum software that lets you send raw SQL calls through a HTML tag. I read a nice security paper written specifically about how to exploit a server running wwwthreads, since it requires a mySQL (or equivelant) server running to store the forum data on.

Was pretty interesting, had information on how to hack your own admin account, get a password list of everyone else on the site, and even, I believe, root the system the mySQL daemon is runnong on if the sysadmin has said daemon running suid root.

(O|||||O)

_________________________
(O|||||O)