Sr. Web Developer
mediabistro.com
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume

Comments for: sporty20001102

Message # 1013238:
Date: 09/06/02 01:50
By: Andy Christianson Profile
Subject: RE: Credit card hack -- will that work??

I did however find that several site (which will go unmentioned) have issues with basic messageboards or commenting. If they already do not filter HTML out of their posts, there can be a great risk to opening up certain issues in the site. For instance, this particular site has a Name and Email text box for posting a comment, you don't need to be registered and the max text length in both boxes seems to be like 50-75 chars... I successfully managed to mess with the html enough to completely fake that I was a registered user. Registered users have a little icon next to them and a link to their profile. This just proves that you can't trust data from users. I'm gonna go check my site over for these bugs =)

Previous Message | Next Message


Comments:
Do you wanna buy Credit Card ?Migawa12/29/04 01:54
how do i hack credit cardstosin11/18/04 13:43
RE: Credit card hack -- will that work??john smith02/07/04 20:29
A generic validation script for web forms?Kelvin Poon09/19/03 11:22
RE: Where to check?Jester04/05/03 12:03
Where to check?Ian10/09/02 02:11
Real Time DataJohn10/06/02 10:27
RE: What about this ?Chris09/23/02 17:02
What about this ?Staffan Söderström09/13/02 06:37
RE: Credit card hack -- will that work??Andy Christianson09/06/02 01:50
RE: Credit card hack -- will that work??Andy Christianson09/03/02 16:51
RE: Javascript form validation workaroundMark Bembnowski08/20/02 11:54
Security of $_POST[]Jeremy Brown07/28/02 15:55
RE: Very dangerous sql code possibleDaniel Tsadok07/16/02 06:24
Javascript form validation workaroundDaniel Tsadok07/16/02 05:56
Somebody has hacked my credit cardParul Asha Singh07/14/02 11:11
RE: When is it too muchHari Usmayadi07/07/02 22:29
check inputWolfgang Hamann04/14/02 03:28
unknown extensionPeter van Rooijen04/03/02 02:13
excellent !!mika02/02/02 09:15
Un Normalised Table Into Un Normalised DataMehmood Ahmed Chadhar09/26/01 03:00
RE: Credit card hack -- will that work??Grasso08/06/01 00:23
RE: ...basic problem..Frans-Jan Wind07/24/01 02:38
Page CachingUnknown07/19/01 02:16
...basic problem..Van Tri05/04/01 08:49
RE: Very dangerous sql code possibleChris Boget04/04/01 13:16
good solutionigor03/22/01 13:24
RE: Credit card hack -- will that work??Michael McGinley03/13/01 11:44
RE: http_reffererJosh03/11/01 02:19
Credit card hack -- will that work??Chuck Clayton02/15/01 11:13
RE: Very dangerous sql code possibleWojtek12/24/00 07:18
RE: http_reffererMichael Rowe11/26/00 00:46
Very dangerous sql code possibleGreg MacLellan11/22/00 12:18
Checking for bad SQLMartijn11/14/00 11:05
http_reffererAdam Zochowski11/13/00 12:51
It's array_push not push_arrayJohn Miller11/10/00 15:34
RE: Also need to strip HTML tags from inputspencer p11/10/00 11:53
Also need to strip HTML tags from inputJohn Lim11/09/00 10:03
RE: When is it too muchspencer p11/04/00 16:59
RE: When is it too muchTim Frank11/03/00 23:38
When is it too muchCCBCREG11/03/00 13:35
ArticleMarc11/03/00 03:14
Excellent !Bjorn Sodergren11/03/00 01:23
 

If you are looking for help, please post on the appropriate forum here. Your questions will be answered much more quickly.

Add A Comment:

Name:

Email:

Subject:

Message:

To reduce spam posts, messages are now manually approved

You are not [logged in]. That means your account will not get credit for this post.