Archives
- ► 2012 (8)
- ► 2011 (157)
- ► 2010 (174)
- ► 2009 (12)
Which topics would you like us to cover more?
Latest comments
- How to reset you Kindle
3, eve...
Thanks for this article and the related "Inside th...
By H K - How to reset you Kindle
3, eve...
How do you drain power on the board? I dont have r...
By Grace - How to reset you Kindle
3, eve...
You're welcome!
By Bas - How to reset you Kindle
3, eve...
Thanks man....removing the battery worked like a c...
By DaveMan - nHapi
example
Hi Slypete, Thank you for your comment. This way w...
By Bas - nHapi
example
Hello, Employing .Net dynamics, one can implement ...
By slypete - Implementing MLLP in C#
Hi Mayura, I'm not sure I understand your question...
By Bas - Implementing MLLP in C#
I have used SSL stream to secure the MLLP transact...
By Mayura
Latest tweets
| XSS so what |
| Written by 0na |
| Thursday, 07 April 2011 08:33 |
|
When searching for information on a site I accidentally discovered that XSS can be done. To be sure I executed the next statement: <h1>test</h1> I try to be subtle. So far, it is just checking. The word was
another one, something related to the topic of the site. Indeed, my
search returns, only in a larger font. Works exactly as html
intended. Now I really want to be sure that my suspicions are
correct and persistent XSS is possible, so I executed that
generally known statement alert(document.cookie). Aaahhhh, what a
nice variety of possibilities. document.getElementById("body_container").innerHtml="<div>Login<form><input id="”password”" /></form>" Another possibility is to catch cookies and send them to your
location. Therefore, you need to register and post a thread. In
your thread you put a script to catch cookies. Every time someone
clicks on your thread the cookie and more information, if you like,
is sent to you. With this cookie, a browser and a cookie editor you
can login and pretend to be that user. |
The right word may be effective, but no word was ever as effective as a rightly timed pause. - Mark Twain




