Author | Post | ||
unknown user |
everthing "could be exploitable" from now on you guys should state why as wel. This isn't an obscure thing, once you know what it is you'll know why. |
||
23.04.2008 10:48:02 |
|
||
aceldama |
fun... |
||
23.04.2008 14:40:34 |
|
||
aceldama |
if you logged in wrongly, what would happen. just wondering as the value tag isn't closed (might have been mentioned before) but my point - and i do have one - is that you can add an onmouseover or something similar as a username if it is repeated and voila, session stolen. no need to add the < or > tags EDIT: just wondering, if it's not xss we're looking for would you be so kind as to let us know? |
||
Edited by aceldama on 23.04.2008 14:51:50 | |||
23.04.2008 14:47:10 |
|
||
Towley |
"Value tag" is closed, since its two single quotes ? |
||
23.04.2008 20:05:50 |
|
||
unknown user |
so round four i guess. No winners. I wonder how bitchy y'all going to be when i finally say what i have in mind. |
||
23.04.2008 22:55:07 |
|
||
DigitalAcid |
I noticed an error message when trying to login. "Your request seems invalid. Try requesting a new page. (forms become invalid when you browse ahead or back)." |
||
24.04.2008 13:38:08 |
|
||
unknown user |
yeah their session stuff will do that. not really my interest right now. |
||
24.04.2008 13:50:33 |
|
||
unknown user |
wow round4 was pretty lame, I guess I better fork over the info soon. O no wait, the majority of their admins have always been bichy. well this was enlightening, I never would have guessed you guys wouldn't get this in 4 days or whatever it was. ah well your loss. |
||
24.04.2008 21:40:49 |
|