Author | Post | |
aceldama![]() ![]() ![]() ![]() |
you can literally type anything - html, javascript, etc - not much (if anything) gets filtered. ![]() ![]() ![]() |
|
Edited by aceldama on 18.12.2006 01:52:22 | ||
![]() |
|
|
unknown user |
I believe it to be poor judgement to post these kinds of things here ... albeit a bit fun ... I'm pretty sure this is not the idea of this board. btw whethe or not you have to sign up is irrelevant for annonimity, you need to reroute/encrypt your traffic. using anonymous proxies, tor, anything else that bounces your connection around enough to prevent your ip to retraced. to pass signup forms these three urls are inresting mailinator.com poolmail.com bugmenot.com only thing that could cause a problem are cc numbers, and there are plenty out there in google, that would pass the luhn 10 formula thingies.. |
|
18.12.2006 06:24:06 |
|
|
aceldama![]() ![]() ![]() ![]() |
the moral of the story - do not employ these things in your websites. there are a few of these guestbooks that were even present in some myspace profiles. now, in view of the recent ![]() ![]() |
|
![]() |
|
|
aceldama![]() ![]() ![]() ![]() |
oh, and i use ![]() ![]() ![]() |
|
Edited by aceldama on 19.12.2006 19:38:06 | ||
![]() |
|
|
unknown user |
yeah, appended thanx. btw XSS isn't an issue in the way you describe it afaik. if it's externally hosted, scripts will run under the credentials of freeguestbook.net Hence not pose any additional thread to your website. That been said, don't use it ![]() |
|
19.12.2006 19:30:16 |
|
|
aceldama![]() ![]() ![]() ![]() |
have you read the "myspace worm" excerpt? i don't know what else to call it. malcode maybe? but i think it's more than that. yes, maybe xss isn't the correct term to use... ...but i am blonde lol ![]() edit: it's more an issue of exploiting those that are viewing your website, not your website itself. like browser redirection, stealing cookie data etc. hope that makes my point more clear. if you store sensitive data in your website, this could help gain a foothold into your system as you could compromise the security of the current user/viewer's private data. (sadly, as is the case with myspace, the badguys can do a lot of damage to whichever person is logged in and checking your profile) |
|
Edited by aceldama on 19.12.2006 19:40:13 | ||
![]() |
|