Author |
Message |
Quan Chi2 Member of "Sexy Teenagers that Code" Group

Age:34 Gender: Joined: Mar 25 2005 Posts: 860 Location: NYC Offline
|
Posted: Sat Oct 14, 2006 4:18 pm Post maybe stupid Post subject: Preventing XSS attacks? |
 |
|
|
|
I know that one of the best ways to prevent XSS attacks is to limit user input, but its I really want to know some other ways if there are any. I'm used to remote file inclusion vulnerabilities, and I know how they work for the most part, but are there techniques for looking through my files to make sure they aren't vulnerable without missing anything? What techniques do you use? |
|
Back to top |
|
 |
Solo Ace Yeah, I'm in touch with reality...we correspond from time to time.

Age:37 Gender: Joined: Feb 06 2004 Posts: 2583 Location: The Netherlands Offline
|
Posted: Sat Oct 14, 2006 5:24 pm Post maybe stupid Post subject: |
 |
|
|
|
'We' don't use a technique, 'we' just know the language 'we' write. |
|
Back to top |
|
 |
Quan Chi2 Member of "Sexy Teenagers that Code" Group

Age:34 Gender: Joined: Mar 25 2005 Posts: 860 Location: NYC Offline
|
Posted: Sat Oct 14, 2006 7:22 pm Post maybe stupid Post subject: |
 |
|
|
|
Well you must have some system you use to go through the files to check for vulnerabilities. :S |
|
Back to top |
|
 |
Cerium Server Help Squatter

Age:42 Gender: Joined: Mar 05 2005 Posts: 807 Location: I will stab you. Offline
|
Posted: Sun Oct 15, 2006 5:56 am Post maybe stupid Post subject: |
 |
|
|
|
In your case: Let someone else code it.
Seriously though, it's just making sure the user has little to no control over the values of important variables (IE: those used in queries or to specify files).
Also, MGB:
When I try to post using the quick reply option, I get a "You must enter a message when posting" error.
Did you take away my ability to use the quick reply? _________________ There are 7 user(s) ignoring me right now. |
|
Back to top |
|
 |
Doc Flabby Server Help Squatter

Joined: Feb 26 2006 Posts: 636 Offline
|
Posted: Sun Oct 15, 2006 7:02 am Post maybe stupid Post subject: |
 |
|
|
|
or do what i do wait untill someone breaks it  _________________ Rediscover online gaming. Get Subspace | STF The future...prehaps |
|
Back to top |
|
 |
The Apache BECAUSE I'M A STUPID IDIOT

Age:33 Gender: Joined: Jul 10 2006 Posts: 294 Location: High Wycombe Offline
|
Posted: Sun Oct 15, 2006 9:35 am Post maybe stupid Post subject: |
 |
|
|
|
Cerium wrote: | Also, MGB:
When I try to post using the quick reply option, I get a "You must enter a message when posting" error.
Did you take away my ability to use the quick reply? |
hmmm, well, i didn't get an error - so yeah, it must be only you. |
|
Back to top |
|
 |
Solo Ace Yeah, I'm in touch with reality...we correspond from time to time.

Age:37 Gender: Joined: Feb 06 2004 Posts: 2583 Location: The Netherlands Offline
|
Posted: Sun Oct 15, 2006 2:48 pm Post maybe stupid Post subject: |
 |
|
|
|
Cerium, uhm, maybe your javascript's disabled or messed up/'secured'?  |
|
Back to top |
|
 |
Cerium Server Help Squatter

Age:42 Gender: Joined: Mar 05 2005 Posts: 807 Location: I will stab you. Offline
|
Posted: Sun Oct 15, 2006 4:03 pm Post maybe stupid Post subject: |
 |
|
|
|
Yup... I installed NoScript recently and I keep forgetting to allow sites I visit.
Didn't even think about it until you guys mentioned it. |
|
Back to top |
|
 |
|