Current location: Hot Scripts Forums » Programming Languages » PHP » Help With Security Problem


Help With Security Problem

Reply
  #1 (permalink)  
Old 05-29-05, 07:41 PM
ozwald ozwald is offline
Newbie Coder
 
Join Date: Apr 2005
Posts: 21
Thanks: 0
Thanked 0 Times in 0 Posts
Help With Security Problem

I was looking on my website, and someone had posted this (exactly as it would appear to any visitor in a browser):

Code:
test security
[_url=javascript:alert('traditional')]normal way[_/url]
[_url=javascript:alert("XSS")]boom[_/url][_url=javascript:alert('XSS'&#41]O_o[_/url]
[_url=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041]more[_/url]
[_url=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29]boom[_/url]
[_url=jav	ascript:alert('XSS');]even more[_/url]
[_url=jav
ascript:alert('XSS');]bad[_/url]
[_url=jav
ascript:alert('XSS');]bad[_/url]
-- Note that I've added "_" so this forum wouldn't process the url tags. Note also that I have [url] tags available to my users, and the links weren't processed on my site.

I did some googling, and from what I can figure this appears to be a cross-site scripting attack. However, I don't know much about these things, and I was wondering the since a lot of the characters appear to have been converted to unicode that this is harmless? I've since deleted it, but if there is a security issue here, how can I deal with it?

Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Free Server Security Audit by Touch Support TSGradyR General Advertisements 0 03-31-05 12:35 AM
Free Security Audit TSGradyR General Advertisements 0 03-15-05 08:29 PM
Count problem kasic ASP.NET 1 10-20-04 01:23 AM
Asp and Microsoft Access 2002 problem gop373 ASP 2 10-06-04 10:13 AM
security concerns new purchased script Ron_Long_Beach PHP 3 09-23-04 02:45 AM


All times are GMT -5. The time now is 12:27 PM.
vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.