2DWorlds Forums
Testing New Signature - Printable Version

+- 2DWorlds Forums (http://2dworlds.buildism.net/forum)
+-- Forum: Off Topic (http://2dworlds.buildism.net/forum/forumdisplay.php?fid=5)
+--- Forum: General Discussion (http://2dworlds.buildism.net/forum/forumdisplay.php?fid=17)
+--- Thread: Testing New Signature (/showthread.php?tid=4497)

Pages: 1 2


RE: Testing New Signature - noob007 - 05-09-2011

(05-09-2011, 07:10 AM)toast Wrote:
(05-09-2011, 03:28 AM)noob007 Wrote:
(05-09-2011, 03:26 AM)toast Wrote:
(05-09-2011, 02:33 AM)noob007 Wrote:
(05-09-2011, 02:27 AM)toast Wrote: Your signature code has XSS vulnerabilities

Erm, no.

kinda yeah if you were able to change the signature variable youd be able to put html code in

But PHP scripts are only server-side. A client can't change them.

What if there was a form (that you make) where you could change your signature and it'd change the value of the variable?

Then it would change the signature because that's what it's supposed to do...


RE: Testing New Signature - Micky - 05-09-2011

O.o??


RE: Testing New Signature - toast - 05-09-2011

(05-09-2011, 02:51 PM)noob007 Wrote:
(05-09-2011, 07:10 AM)toast Wrote:
(05-09-2011, 03:28 AM)noob007 Wrote:
(05-09-2011, 03:26 AM)toast Wrote:
(05-09-2011, 02:33 AM)noob007 Wrote: Erm, no.

kinda yeah if you were able to change the signature variable youd be able to put html code in

But PHP scripts are only server-side. A client can't change them.

What if there was a form (that you make) where you could change your signature and it'd change the value of the variable?

Then it would change the signature because that's what it's supposed to do...

Someone could enter "<script>evil javascript here stealing users cookies and sending them to bulgaria</script>" as their signature and it'd put the javascript code in


RE: Testing New Signature - Fat_Sacks - 05-09-2011

Wut?


RE: Testing New Signature - toast - 05-09-2011

read


RE: Testing New Signature - Qwertygiy - 05-09-2011

The only problem?

<a href="http://buildism.net">This code does not work in the forums.</a>


RE: Testing New Signature - Paradox - 05-09-2011

(05-09-2011, 03:13 AM)noob007 Wrote:
(05-09-2011, 03:00 AM)Paradox Wrote:
(05-09-2011, 02:33 AM)noob007 Wrote:
(05-09-2011, 02:27 AM)toast Wrote: Your signature code has XSS vulnerabilities

Erm, no.

Coder fight?

<_<

How mature the moderators are...

That wasn't meant to be taken seriously. I am very mature. I just find it annoying that the one time I try to have fun, I get criticized for it.