DEV Community

Discussion on: What Are Some of the Worst Security Practices You’ve Ever Seen in Software Development?

Collapse
 
jcubic profile image
Jakub T. Jankiewicz

I once was fixing PHP site where there was a login page but other php pages did not check if user was logged, and "hidden" pages were trivial to guess. The site was created by some high schooler and other not related high schoolers (probbaly) was messing with the site without the admin password or a need to login. The owner said that the images that he upload was disappearing, it was funny actally to see why by looking at the code.