Testing New Signature
#11
(05-09-2011, 07:10 AM)toast Wrote:
(05-09-2011, 03:28 AM)noob007 Wrote:
(05-09-2011, 03:26 AM)toast Wrote:
(05-09-2011, 02:33 AM)noob007 Wrote:
(05-09-2011, 02:27 AM)toast Wrote: Your signature code has XSS vulnerabilities

Erm, no.

kinda yeah if you were able to change the signature variable youd be able to put html code in

But PHP scripts are only server-side. A client can't change them.

What if there was a form (that you make) where you could change your signature and it'd change the value of the variable?

Then it would change the signature because that's what it's supposed to do...
Reply
#12
O.o??
Reply
#13
(05-09-2011, 02:51 PM)noob007 Wrote:
(05-09-2011, 07:10 AM)toast Wrote:
(05-09-2011, 03:28 AM)noob007 Wrote:
(05-09-2011, 03:26 AM)toast Wrote:
(05-09-2011, 02:33 AM)noob007 Wrote: Erm, no.

kinda yeah if you were able to change the signature variable youd be able to put html code in

But PHP scripts are only server-side. A client can't change them.

What if there was a form (that you make) where you could change your signature and it'd change the value of the variable?

Then it would change the signature because that's what it's supposed to do...

Someone could enter "<script>evil javascript here stealing users cookies and sending them to bulgaria</script>" as their signature and it'd put the javascript code in
[Image: 5widdh.png]
Siggy by McNoobster!
[Image: loading.gif]
Reply
#14
Wut?
[Image: 76561198037039305.png]
[Image: nmdd7o.gif]
Reply
#15
read
[Image: 5widdh.png]
Siggy by McNoobster!
[Image: loading.gif]
Reply
#16
The only problem?

<a href="http://buildism.net">This code does not work in the forums.</a>
Reply
#17
(05-09-2011, 03:13 AM)noob007 Wrote:
(05-09-2011, 03:00 AM)Paradox Wrote:
(05-09-2011, 02:33 AM)noob007 Wrote:
(05-09-2011, 02:27 AM)toast Wrote: Your signature code has XSS vulnerabilities

Erm, no.

Coder fight?

<_<

How mature the moderators are...

That wasn't meant to be taken seriously. I am very mature. I just find it annoying that the one time I try to have fun, I get criticized for it.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)