Topic: "[ended - no winners] QUIZ: what's wrong with this part of the wechall website" (page 2 of 4)

< 1 2 3 4 >
Author Post
unknown user
csrf key does not hold my interest.

Nor does the duplicate ID.

all valid I guess, but i'm looking for that one thing .. You know ...
EMail
theAnswer
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
The line break in <DIV CLASS='website'>?
User number is not 202 but 203?
Something about the nbsp's?

No idea. Appearently it's not about clean html code.
private message
unknown user
QuoteQuote from theAnswer:

No idea. Appearently it's not about clean html code.


:-) yeah i'm being a bit cruel.

as you might suspect it's security related. I didn't post it in the vulnerable code section, beause i'm to lazy to generate an exploit. And it's so blatantly obvious ...

so round 2:
think security
EMail
quangntenemy
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
OK so it's insecure because it's php? ROFL
Well maybe u can make it more secure by encrypting the password before sending so that sniffing won't work.
But maybe I'm thinking way too hard :P
private message EMail Website
Z
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
I think it is related to the "name='csrf_key' VALUE='xxxx' .. part, but dunno what you can do with this...
private message
unknown user
o come on.

some of the members here must have deved a serious website?
EMail
quangntenemy
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Hmm maybe lack of meta tags for SEO? ^^
private message EMail Website
unknown user
SEO has rarely ever interested me.
EMail
DigitalAcid
groupmastergroupmastergroupmaster
Sql injection ?
Or change the method='post' to method='get' ?
8-)
private message EMail
theAnswer
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
/css.css, /favicon.ico, /login.php etc
The slashes are waste... :P
private message

Topic: "[ended - no winners] QUIZ: what's wrong with this part of the wechall website" (page 2 of 4)

< 1 2 3 4 >