Quote:And it will block plenty of legit requests too.
well, not so many at all. One should remove select, insert ....
(02-09-2011 10:07 AM)ZiNgA BuRgA Wrote: try something more complex than a very simple request URL filter.
These are only to prevent sql, xss.
There are (on the blog I mentioned above) various things for protection.
Being a coder you can recognize holes in plugins, but you are just 1% of mybb users who are able to do that. Talking about an ordinary mybb owners, these protections are good.