in reply to Re: Re: Filtering potentially dangerous URI schemas in <a href="...">
in thread Filtering potentially dangerous URI schemas in <a href="...">
About petrucio's password hash hack... It is not so bad because it only shows the encrypted pwd and can only access cookies related to Perlmonks. With current JS security, I believe that unless you send email messages, you can only talk to the server the page came from.If I can display your cookie to you, I can send it to me. If I can get your cookie, I can login as you.
I'm not sure what is allowed nowadays in scripts on home nodes, and I didn't go check the script in question (I'm pretty sure Petruchio is *not* sending it anywhere anyways) but the above should be true unless someone actually took a lot of time parsing and allowing certain js commands and not others. :)
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: Re(3): Filtering potentially dangerous URI schemas in <a href="...">
by hackmare (Pilgrim) on Oct 21, 2002 at 15:20 UTC | |
by Dog and Pony (Priest) on Oct 22, 2002 at 11:52 UTC | |
by Aristotle (Chancellor) on Oct 22, 2002 at 12:56 UTC | |
by zigdon (Deacon) on Oct 22, 2002 at 13:07 UTC | |
by Aristotle (Chancellor) on Oct 22, 2002 at 13:22 UTC | |
by Dog and Pony (Priest) on Oct 22, 2002 at 13:41 UTC | |
by Aristotle (Chancellor) on Oct 22, 2002 at 15:24 UTC | |
by Dog and Pony (Priest) on Oct 22, 2002 at 09:41 UTC | |
by zigdon (Deacon) on Oct 22, 2002 at 14:01 UTC | |
by hackmare (Pilgrim) on Oct 23, 2002 at 08:04 UTC |