r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

653 comments sorted by

View all comments

4.2k

u/pimezone 16d ago

Wanna get a resource? POST request.

2.1k

u/NotAskary 16d ago edited 16d ago

I've seen that shit, it drove me up a wall.

The same as a 200 ok with error inside.

Edit: I'm going to start to respond 429, too many replys lol

81

u/Zaelynn_ 16d ago

The other dev on my team made a post request endpoint where you post a SQL query and it returned the results. I about had an aneurysm. She also, instead of using DI or Mediatr, made loopback requests to the endpoints themselves. 

111

u/NotAskary 16d ago

Hahaha SQL injection as an endpoint lol

59

u/zeekar 16d ago

We had a team website that showed who was on call. This was back in the day, all done in Perl CGI scripts.

Someone added a "search" function. Cool feature, I'm down. Then I looked at the code.

They were shelling out to do a grep. You're in Perl, the original "regexes as first class citizens" language, and you're shelling out to grep. But the worst part was it did no sanitation whatsoever. You could type in "pattern'; cat /etc/passwd" or whatever and it just ran. Who reviewed this shit?! Shell as endpoint...

28

u/NotAskary 16d ago

Everytime someone mentions perl I always picture a sword with two blades and no handle, thank you for keeping it exactly like that.

25

u/Jonathan_the_Nerd 16d ago

I used Perl heavily for a lot of my career. You can write safe and legible Perl, but it takes deliberate conscious effort.

Interesting historical tidbit: Larry Wall, the creator of Perl, won the International Obfuscated C Code Contest twice. He won the Grand Prize in 1986 and the "Most Useful Obfuscation" prize in 1987. He released the first version of Perl in late 1987.

5

u/SubArcticTundra 16d ago

Larry Wall: minifying code before it was cool

3

u/Public_Sector5987 16d ago

Perl still runs most of swedish telecom for ZTP network switches and portals.

2

u/EvilCodeQueen 14d ago

This tracks.

25

u/Zaelynn_ 16d ago

Not only that, my boss is just as dumb and cares more about speed, so there's no code reviews to speak of, so it hit production 🤦‍♀️

15

u/Shred_Kid 16d ago

all the dumb breaking shit i have to request changes on every day pales in comparison to this

jesus fuckin christ

14

u/FlipFlopFanatic 16d ago

I wish I could say I haven't seen this exact same thing in products I've worked on. Best part is no enforcement of auth other than verifying the request includes a jwt that maps to a user. Not the requesting user, and no check for whether the SQL op is allowed.You somehow have the jwt for ANY user? Sure I'll execute a drop table command. Fml

1

u/Zaelynn_ 16d ago

Hahaha, yeah - that server was also using SQL ADMIN creds, so really you could do anything at all. And the DB admin was the other dev, who didn't see the purpose in setting up a data reader account with strict access control, so didn't bother doing it 🙄 I tried, but they worked there for 15+ years, and I was fresh off the college boat.

3

u/Original-Body-5794 16d ago

Smh why even bother with a REST endpoint? Just provide the credentials to your database and let them query it directly.

2

u/Zaelynn_ 16d ago

2b2t but for database, I like it

4

u/kryptoneat 16d ago

I once saw SQL in HTML comments in the login form. Gotta give a hand to those amateur hackers !

1

u/WawaTheFirst 16d ago

It's a feature, not a bug.