Server Help Forum Index Server Help
Community forums for Subgame, ASSS, and bots
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   StatisticsStatistics   RegisterRegister 
 ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin (SSL) 

Server Help | ASSS Wiki (0) | Shanky.com
Preventing XSS attacks?

 
Post new topic   Reply to topic Printable version
 View previous topic  Pranksters get a poor woman to delete ... Post :: Post Hard to figure out what I want to be.  View next topic  
Author Message
Quan Chi2
Member of "Sexy Teenagers that Code" Group
Member of


Age:34
Gender:Gender:Male
Joined: Mar 25 2005
Posts: 860
Location: NYC
Offline

PostPosted: Sat Oct 14, 2006 4:18 pm   Post maybe stupid    Post subject: Preventing XSS attacks? Reply to topic Reply with quote

I know that one of the best ways to prevent XSS attacks is to limit user input, but its I really want to know some other ways if there are any. I'm used to remote file inclusion vulnerabilities, and I know how they work for the most part, but are there techniques for looking through my files to make sure they aren't vulnerable without missing anything? What techniques do you use?
Back to top
View users profile Send private message Add User to Ignore List Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Solo Ace
Yeah, I'm in touch with reality...we correspond from time to time.


Age:37
Gender:Gender:Male
Joined: Feb 06 2004
Posts: 2583
Location: The Netherlands
Offline

PostPosted: Sat Oct 14, 2006 5:24 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

'We' don't use a technique, 'we' just know the language 'we' write.
Back to top
View users profile Send private message Add User to Ignore List
Quan Chi2
Member of "Sexy Teenagers that Code" Group
Member of


Age:34
Gender:Gender:Male
Joined: Mar 25 2005
Posts: 860
Location: NYC
Offline

PostPosted: Sat Oct 14, 2006 7:22 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Well you must have some system you use to go through the files to check for vulnerabilities. :S
Back to top
View users profile Send private message Add User to Ignore List Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Cerium
Server Help Squatter


Age:42
Gender:Gender:Male
Joined: Mar 05 2005
Posts: 807
Location: I will stab you.
Offline

PostPosted: Sun Oct 15, 2006 5:56 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

In your case: Let someone else code it.



Seriously though, it's just making sure the user has little to no control over the values of important variables (IE: those used in queries or to specify files).



Also, MGB:
When I try to post using the quick reply option, I get a "You must enter a message when posting" error.
Did you take away my ability to use the quick reply?
_________________
There are 7 user(s) ignoring me right now.
Back to top
View users profile Send private message Add User to Ignore List AIM Address
Doc Flabby
Server Help Squatter


Joined: Feb 26 2006
Posts: 636
Offline

PostPosted: Sun Oct 15, 2006 7:02 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

or do what i do wait untill someone breaks it biggrin.gif
_________________
Rediscover online gaming. Get Subspace | STF The future...prehaps
Back to top
View users profile Send private message Add User to Ignore List
The Apache
BECAUSE I'M A STUPID IDIOT


Age:33
Gender:Gender:Male
Joined: Jul 10 2006
Posts: 294
Location: High Wycombe
Offline

PostPosted: Sun Oct 15, 2006 9:35 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

Cerium wrote:
Also, MGB:
When I try to post using the quick reply option, I get a "You must enter a message when posting" error.
Did you take away my ability to use the quick reply?


hmmm, well, i didn't get an error - so yeah, it must be only you.
Back to top
View users profile Send private message Add User to Ignore List Send email MSN Messenger
Solo Ace
Yeah, I'm in touch with reality...we correspond from time to time.


Age:37
Gender:Gender:Male
Joined: Feb 06 2004
Posts: 2583
Location: The Netherlands
Offline

PostPosted: Sun Oct 15, 2006 2:48 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Cerium, uhm, maybe your javascript's disabled or messed up/'secured'? tongue.gif
Back to top
View users profile Send private message Add User to Ignore List
Cerium
Server Help Squatter


Age:42
Gender:Gender:Male
Joined: Mar 05 2005
Posts: 807
Location: I will stab you.
Offline

PostPosted: Sun Oct 15, 2006 4:03 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Yup... I installed NoScript recently and I keep forgetting to allow sites I visit.

Didn't even think about it until you guys mentioned it.
Back to top
View users profile Send private message Add User to Ignore List AIM Address
Display posts from previous:   
Post new topic   Reply to topic    Server Help Forum Index -> Trash Talk All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
View online users | View Statistics | View Ignored List


Software by php BB © php BB Group
Server Load: 127 page(s) served in previous 5 minutes.

phpBB Created this page in 0.679392 seconds : 32 queries executed (80.5%): GZIP compression disabled