@joepie91 oh god, they're not sanitizing their inputs are they

@senhara I think this *is* their sanitization

· · Web · 2 · 0 · 2

@senhara (And I suspect that that password is getting string-interpolated into some kind of API call or shell command that goes into another system which needs to create a local account for every system-wide account, or something)

@joepie91 couldn't you toss it into `base64` and let the other end of the API or something decode it to handle it safely????

@senhara In theory you could (assuming you control the other end's implementation) but I do not get the impression that this thing was built by particularly security-conscious developers

Sign in to participate in the conversation

Small server part of the pixie.town infrastructure. Registration is closed.