Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6841395
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T23:57:40+00:00 2026-05-26T23:57:40+00:00

Ok, guys, I’ve been thinking and thinking and thinking, and now finally out of

  • 0

Ok, guys, I’ve been thinking and thinking and thinking, and now finally out of ideas…

So I’ve devolped this WordPress plugin, that takes customers info from a SQL DB on my server, through cURL.

So this is what happens:

Each user that downloads the plugin from my site has a unique ID which is generated from Mysql (auto_increment). This ID is stored in the plugin on download. The plugin then uses this ID to select a row and take some info (sensetive info) in my db on my server, using cURL.

So, here’s how it fetches the info:

1.) The unique ID is $_POST‘ed to the target page (my_curl.php)

2.) A preg_match is ran on the posted ID to help prevent any silly SQL injections.

3.) The row is selected and the info is fetched.

4.) The info fetched from the DB gets JSON ENCODE.

Now anyone can just go in to the plugins files, and do this:

if their copy of the plugin was assigned to the id: 21645875457

they go in and change that id to one up or down: 21645875458 or 21645875456.

they then run the plugin, and they see someone elses sensetive info….

Can anybody come up with a few suggestions, to prevent this. I know its close to impossible, but there’s got to be something, right?

If i send some more info from the plugin to the curl target, the evil moster could just simply change that.

Another peice of info that is in the DB is the domain the plugin is assigned to.

I was thinking of posting the current domain ($_SERVER['HTTP_HOST']) to the cURL page and have it verified with the ID (check if the domain is in the same row as the ID).

That would make it harder for the attacker as they will need to know the ID AND the domain they want to steal the info from but i need something more secure…

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T23:57:40+00:00Added an answer on May 26, 2026 at 11:57 pm

    An easy way to increase the entrophy of the ID-to-info mapping (or, as you suggest, ID-and-host-to-customer mapping) is to not use sequential IDs, but instead assign something more complex like, say, a generated UUID.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

guys am having some troubles with running out of memory when displaying an animation
Guys, I've came across this problem I can't resolve myselg, I'm pretty sure I
Guys this is driving me crazy.. I am amateur in the mod_rewrite topic.. I
guys. I've been searching for an answer for my issue the whole morning, but
Guys that is code copied from a book (Programming Windows 5th edition): #include <windows.h>
guys i have a xml file which is like this: <Point TestFlag=0 id=1 name=Conversation
guys i got a php file that use it as xml for a flash
Guys I have been trying lots of different options from cutting up to building
Guys, Can you please tell me that ,I wants to learn Azure , by
Guys I asked a similar question like this earlier since I was unable to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.