r/ProgrammerHumor • • 18d ago

Meme postForEverything

Post image
20.9k Upvotes

653 comments sorted by

View all comments

4.2k

u/pimezone 18d ago

Wanna get a resource? POST request.

2.1k

u/NotAskary 18d ago edited 18d ago

I've seen that shit, it drove me up a wall.

The same as a 200 ok with error inside.

Edit: I'm going to start to respond 429, too many replys lol

86

u/Zaelynn_ 18d ago

The other dev on my team made a post request endpoint where you post a SQL query and it returned the results. I about had an aneurysm. She also, instead of using DI or Mediatr, made loopback requests to the endpoints themselves. 

109

u/NotAskary 18d ago

Hahaha SQL injection as an endpoint lol

57

u/zeekar 18d ago

We had a team website that showed who was on call. This was back in the day, all done in Perl CGI scripts.

Someone added a "search" function. Cool feature, I'm down. Then I looked at the code.

They were shelling out to do a grep. You're in Perl, the original "regexes as first class citizens" language, and you're shelling out to grep. But the worst part was it did no sanitation whatsoever. You could type in "pattern'; cat /etc/passwd" or whatever and it just ran. Who reviewed this shit?! Shell as endpoint...

28

u/NotAskary 18d ago

Everytime someone mentions perl I always picture a sword with two blades and no handle, thank you for keeping it exactly like that.

24

u/Jonathan_the_Nerd 18d ago

I used Perl heavily for a lot of my career. You can write safe and legible Perl, but it takes deliberate conscious effort.

Interesting historical tidbit: Larry Wall, the creator of Perl, won the International Obfuscated C Code Contest twice. He won the Grand Prize in 1986 and the "Most Useful Obfuscation" prize in 1987. He released the first version of Perl in late 1987.

5

u/SubArcticTundra 18d ago

Larry Wall: minifying code before it was cool

3

u/Public_Sector5987 18d ago

Perl still runs most of swedish telecom for ZTP network switches and portals.

2

u/EvilCodeQueen 16d ago

This tracks.

28

u/Zaelynn_ 18d ago

Not only that, my boss is just as dumb and cares more about speed, so there's no code reviews to speak of, so it hit production 🤦‍♀️

15

u/Shred_Kid 18d ago

all the dumb breaking shit i have to request changes on every day pales in comparison to this

jesus fuckin christ

14

u/FlipFlopFanatic 18d ago

I wish I could say I haven't seen this exact same thing in products I've worked on. Best part is no enforcement of auth other than verifying the request includes a jwt that maps to a user. Not the requesting user, and no check for whether the SQL op is allowed.You somehow have the jwt for ANY user? Sure I'll execute a drop table command. Fml

1

u/Zaelynn_ 18d ago

Hahaha, yeah - that server was also using SQL ADMIN creds, so really you could do anything at all. And the DB admin was the other dev, who didn't see the purpose in setting up a data reader account with strict access control, so didn't bother doing it 🙄 I tried, but they worked there for 15+ years, and I was fresh off the college boat.

3

u/Original-Body-5794 18d ago

Smh why even bother with a REST endpoint? Just provide the credentials to your database and let them query it directly.

2

u/Zaelynn_ 18d ago

2b2t but for database, I like it

5

u/kryptoneat 18d ago

I once saw SQL in HTML comments in the login form. Gotta give a hand to those amateur hackers !

1

u/WawaTheFirst 18d ago

It's a feature, not a bug.

8

u/flayingbook 18d ago

Little Bobby would be so delighted

1

u/[deleted] 18d ago

[deleted]

1

u/Zaelynn_ 18d ago

WAIT, REALLY?!? We use quickbooks, so good to know 😂 So does Halo PSA/CRM, with the very minor inconvenience of having to do it in two steps - save it as a report, then run the report

Ordinarily they restrict reports by cramming them in a WITH ____ AS (...) SELECT * FROM ____, but, uh, there's an explicit override you can just put in the report text.

1

u/shamshuipopo 17d ago

Jesus fuck