Skip to content

Comment on Saved 10 billion DNS queries per month by disabling DNS Prefetching

Comments

That's all very nice, but it seems to do more with the fact that each person gets his/her own subdomain. And given that I found three xss's in about five minutes [edit: and then like ten more in the next five seconds, after realizing any input box works] doesn't give me confidence in their abilities.

http://www.pinkbike.com/news/search/?q=%3C%2Ftitle%3E%3Cscri...

http://www.pinkbike.com/product/compare/?items=466,%22%3E%3C...

http://www.pinkbike.com/photo/list/?date=all&text=%3C/ti...

http://www.pinkbike.com/buysell/list/?q=%3Cscript%3Ealert%28...

http://www.pinkbike.com/forum/search/?q=%3C/title%3E%3Cscrip...

Edit: I've stopped adding xss's. It's actually harder to find input boxes which don't lead to xss's than ones which do.

Whoever it was that fixed the XSS (necro?), I'm impressed how fast that was.

But please don't rely on just escaping < and >. You have to worry about double-quotes too, I can end a string and add a "onload" or "onfocus" attribute if it's already in a tag. And sometimes you have to worry about single quotes. In fact, there's a lot to take a look at.

Instead of just fixing the case at hand, try to be proactive about it. Check to make sure you don't have anything else.

Edit: Click the search box, for example. http://www.pinkbike.com/forum/search/?q=%22%20onclick=%22ale...

Yup. I actually wrote a filter to our framework when it was built years ago, but as new people help out on dev they don't always use the framework. My bad and I do appreciate the smack. I humbly bow to you with egg on my face.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.