 |
|
| Coding Forum Problems with your code? Discuss coding issues, including JavaScript, PHP & MySQL, HTML & CSS, Flash & ActionScript, and more. |
|
 |
|

02-03-2004, 06:20 PM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
|
ok next thing u need to do is apply the same HTML removal to all the fields not just the comment!
|

02-03-2004, 06:35 PM
|
|
Banned
Latest Blog: None
|
|
Join Date: 01-23-04
Posts: 1,098
|
|
|
lets make it play like 1000 flash movies and exeed his bandwich limit.
|

02-03-2004, 06:36 PM
|
|
Banned
Latest Blog: None
|
|
Join Date: 01-23-04
Posts: 1,098
|
|
|
damn you jim, now i cant do what i wanted to do, coulda at least just use a pop up window. =(
|

02-03-2004, 06:37 PM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
lol i made a little tool where i can type any strings and because the <script> tag works in the Name: field I can execute it!
I put this in the name field to change the title to "LazyJim" then alert it, then go to another site  ...
[code:1:99ffeb4b80]<script>document.location=String.fromCharCode(106, 97,118,97,115,99,114,105,112,116,58,105,102,32,40, 100,111,99,117,109,101,110,116,46,116,105,116,108, 101,61,39,76,97,122,121,74,105,109,39,41,32,97,108 ,101,114,116,40,39,76,97,122,121,74,105,109,39,41, 59,118,111,105,100,40,100,111,99,117,109,101,110,1 16,46,108,111,99,97,116,105,111,110,61,39,104,116, 116,112,58,47,47,119,119,119,46,97,108,112,104,97, 45,109,97,116,114,105,120,45,100,101,115,105,103,1 10,46,99,111,46,117,107,47,105,109,103,47,104,99,1 05,95,100,114,101,97,109,46,104,116,109,108,39,41) </script>[/code:1:99ffeb4b80]
|

02-03-2004, 06:37 PM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
Sorry sim
|

02-03-2004, 06:41 PM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
|
ok i added another hack to stop the one before from working
|

02-03-2004, 06:42 PM
|
|
Banned
Latest Blog: None
|
|
Join Date: 01-23-04
Posts: 1,098
|
|
|
now i cant post ;[
|

02-03-2004, 06:51 PM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
|
why not?
*edit* link to posting page at the top of comments page (not just the bottom)
|

02-03-2004, 07:27 PM
|
 |
Senior Member
Latest Blog: None
|
|
Join Date: 10-12-03
Location: Minnesota, USA
Posts: 939
|
|
|
You guys did all that destruction just in the comments box? I said I hadn't fixxxed the others yet!
|

02-03-2004, 07:29 PM
|
 |
Super Trooper
Latest Blog: None
|
|
Join Date: 10-12-03
Posts: 4,819
|
|
Quote:
|
Originally Posted by Ferre
Quote:
|
Originally Posted by Brian
Add an option so an admin can directly reply to an entry in the guestbook, and the admins entry will show up in the entry he was rpelying too. (get what I mean? Hard for me to rexplain it ...)
|
I guess he means to say "copy advanced guestbook" :wink:
I use it at the ministry's website and it has everything this script misses.
|
Suggesting one feature that multiple guestbook scripts have (not just AG  ), isn't copying AG.
LoM - Looking better.  You going to submit it to hotscripts?
__________________
badum tish.
|

02-03-2004, 07:34 PM
|
 |
Senior Member
Latest Blog: None
|
|
Join Date: 10-12-03
Location: Minnesota, USA
Posts: 939
|
|
|
Yes I will, but first I want to make sure it's solid, I still need to fix the other fields (if comments is even fixed) then make a few styles for it.
I'm also going to make a MySQL version...
|

02-03-2004, 08:22 PM
|
|
Banned
Latest Blog: None
|
|
Join Date: 01-23-04
Posts: 1,098
|
|
Maybe you want to fix my topsite list script? i'll give you half credit then we submit it to hotscripts. www.po2.net/topsite.php might still work. DONT GO POSTING HTML, IM SERIOUS, i'll GET REAL MAD NO LIE
|

02-03-2004, 08:26 PM
|
 |
Senior Member
Latest Blog: None
|
|
Join Date: 10-12-03
Location: Minnesota, USA
Posts: 939
|
|
I could make a script for you when the guestbook is complete
Did you wreck the site inside the comments box?
|

02-03-2004, 08:30 PM
|
|
Banned
Latest Blog: None
|
|
Join Date: 01-23-04
Posts: 1,098
|
|
|
i dont need you to make me a script, my script is done. Just buggy (same problems you got) html being posted cause errors. And i used flat files.
i havnt wrecked your guest book since last night.
|

02-03-2004, 08:32 PM
|
 |
Senior Member
Latest Blog: None
|
|
Join Date: 10-12-03
Location: Minnesota, USA
Posts: 939
|
|
|
Well who did wreck it? I need to know where and how...
|

02-04-2004, 03:34 AM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
I wasn't doing it in the comments box sorry!
I'm not an expert i was just playing around with any JavaScript i could get into the other fields!
I think you need someone with deeper knowledge of PHP or whatever language u wrote it in to test the comments box.
|

02-04-2004, 03:44 AM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
|
Can we see you script please?
if it's going to be on hotscripts people might look up the workings of it before attaking a guestbook.
|

02-04-2004, 10:12 AM
|
|
Banned
Latest Blog: None
|
|
Join Date: 01-23-04
Posts: 1,098
|
|
|
i attacked the comments box the first time with html code. i think theres a php function striphtml or striptags.
|

02-04-2004, 10:46 AM
|
 |
v7n Mentor
Latest Blog: None
|
|
Join Date: 10-13-03
Location: UK
Posts: 2,469
|
|
|
yeah i was wondering how to get past the strip-html-tags and/or convert-to-entities filters, but I'm not that experienced with PHP. I did read those functions can have problems with <!DOCTYPE> declarations though I'm not sure how it can help take advantage of the thing.
If the facility is left not secure (ppl will keep on finding ways to get through anyway), the biggest threat is to readers having malicious code installed on their machine (in the same way any site can); to sensitive info on the server being accessed; malicious scripts/code being installed on the server.
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -7. The time now is 03:44 AM.
Powered by vBulletin Copyright © 2000-2013 Jelsoft Enterprises Limited.
Copyright © 2003 - 2013 Escalate Media LP
|
|
|