View Full Version : "DEFACED!"... what the #&%$?!
ctfoto
01-27-2006, 08:26 AM
i got a comment on my photoblog (http://www.ctfoto.com/blog/) that just said:
'by dsssssssss - '
and now when i go in my comment admin, i get this evil thing, blocking me from my comment page:
http://images6.theimagehosting.com/defaced.gif
am i being punished for something bad i've done, or is this a virus?
se.nsuo.us
01-27-2006, 08:28 AM
See http://forum.pixelpost.org/showthread.php?t=3245 - and it is nothing serious just some kid having fun :)
tinyblob
01-27-2006, 08:34 AM
it is serious...
serious because it's evidence that there are issues in Pixelpost that should've been resolved a long time ago. but we've been too busy adding nice new features to fix old problems.
hopefully this will be a reality check.
Before final version we can fix it by cutting off tags which isnt:
b, i, u, p, br.
I also have comment with it in content:
<META http-equiv="refresh" content="0; URL=http://images6.theimagehosting.com/defaced.gif">
But it isnt big case. I switched off redirecting and Im switching this comments off.
se.nsuo.us
01-27-2006, 09:34 AM
strip_tags has a second arguement which tells which tags to allow
Yeah, that is why Im talking about it :)
se.nsuo.us
01-27-2006, 10:07 AM
Yeah, that is why Im talking about it :)
Heh! but that won't prevent us against countless other forms of XSS for example LOL deleted this as even this form allows XSS
or
javascript:alert('XSS')
One step at a time? ;)
ctfoto
01-27-2006, 04:41 PM
geez.... i wish i knew what you guys were talking about. i am just a "noob", after all....
so, the -Defaced- image is gone now, but the link's still there. one user suggested that if i was fast enough in my comments admin i could delete the comment before the link has time to take over.... urrrgghh, i'm trying.....
and, sorry, but whether or not this is serious, it sure ain't fun....
hey, 'dssssssss'... you out there? let's hear your voice, little boy...
ctfoto
01-27-2006, 04:52 PM
hey, by the way... thanks PixelPost team for your help. i know it ain't your fault - and really do appreciate all the hours y'all put into this.
-ct
True - hex coded code can be also not secure :/
vBulletin® v3.7.3, Copyright ©2000-2013, Jelsoft Enterprises Ltd.