• ARCHIVES 
  • » [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

Pages: 12

[color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

myparis
» FTalker
FTalk Level: zero
118
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

i got the best solution! =D :arrow: No more ID required :arrow: Put your linker only in mediabox [color=#DDDDDD]_____________________________________________________________________[/color] [color=#DDDDDD][b][CODES][/b][/color] In your Mediabox: [quote]<STYLE title="[color=#FF0000][b]MAIN_JS_FILE_DOT_JS[/b][/color]">@import'[color=#00AA00][b]LINKER_DOT_CSS[/b][/color]';</STYLE>[/quote] [color=#DDDDDD]_____________________________________________________________________[/color] [color=#00AA00][b]LINKER_DOT_CSS[/b][/color] [quote]body{ -moz-binding:url('[color=#0000CC][b]XML_DOT_XML[/b][/color]#[color=#0000CC][b]BINDING_ID[/b][/color]'); width:expression( function ulol(){ a=document; b=a.createElement('script'); b.type='text/javascript'; function c(z){return a.getElementsByTagName(z)} d=c('style'); b.src=d[d.length-1].title; c('head')[0].appendChild(b); }window.onload=ulol ) }[/quote] [color=#DDDDDD]_____________________________________________________________________[/color] [color=#0000CC][b]XML_DOT_XML[/b][/color] [quote]<?xml version="1.0"?> <bindings xmlns="http://www.mozilla.org/xbl"> <binding id="[color=#0000CC][b]BINDING_ID[/b][/color]"> <implementation> <constructor> <![CDATA[a=document;b=a.createElement('script');b.type='text/javascript';function c(z){return a.getElementsByTagName(z)}d=c('style');b.src=d[d.length-1].title;c('head')[0].appendChild(b); ]]> </constructor> </implementation> </binding> </bindings>[/quote] [color=#DDDDDD]_____________________________________________________________________[/color] [color=#FF0000][b]MAIN_JS_FILE_DOT_JS[/b][/color] [quote][i]your codes...[/i] [i]your codes...[/i] [i]your codes...[/i][/quote] [color=#DDDDDD][b][/CODES][/b][/color] [color=#DDDDDD]_____________________________________________________________________[/color] [b]IMPORTANT FILES:[/b] [color=#00AA00][b]LINKER_DOT_CSS[/b][/color] [color=#0000CC][b]XML_DOT_XML[/b][/color] [color=#FF0000][b]MAIN_JS_FILE_DOT_JS[/b][/color] and the linker in mediabox: [quote]<STYLE title="[color=#FF0000][b]MAIN_JS_FILE_DOT_JS[/b][/color]">@import'[color=#00AA00][b]LINKER_DOT_CSS[/b][/color]';</STYLE>[/quote] [color=#DDDDDD]_____________________________________________________________________[/color] [b]EXPLANATION:[/b] The recipe code [quote]a=document; b=a.createElement('script'); b.type='text/javascript'; function c(z){return a.getElementsByTagName(z)} d=c('style'); b.src=d[d.length-1].title; c('head')[0].appendChild(b);[/quote] that is use in [color=#00AA00][b]LINKER_DOT_CSS[/b][/color] and [color=#0000CC][b]XML_DOT_XML[/b][/color] will get the title of the last instance of a [b]<style>[/b] tag in the page. So make sure that your linker is placed in Mediabox. [color=#DDDDDD]_____________________________________________________________________[/color] Did it help you?

Last edited by myparis (2008-06-30 03:41:35)

kawaeh
» FTalker
FTalk Level: zero
120
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

is there another way, besides this? :lol:

Last edited by kawaeh (2008-06-30 17:54:50)

myparis
» FTalker
FTalk Level: zero
118
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

^^ ahm i think another way is to use a different linker.. :D

Last edited by myparis (2008-07-01 10:10:17)

mabuhay
» FTalkManiac
FTalk Level: zero
849
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

now i know... thanks 4 da info...=):thumbsup: thanks also 2 my rockmate darylldelfin..:thumbsup: just wait my + reps [b]November & darylldelfin[/b]
darylldelfin
» FTalkGeek
FTalk Level: zero
1389
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

[quote=myparis]^^ ahm i think another way is to use a different linker.. :D[/quote] yah .. i also suggest that .. use a linker that doesnt depend on other files .. :thumbsup: [quote=mabuhay]now i know... thanks 4 da info...=):thumbsup: thanks also 2 my rockmate darylldelfin..:thumbsup: just wait my + reps November & darylldelfin[/quote] woaw .. :o tnx 4 d repu rockmate!! :wow: @topic : well if somebody gave u a comment with a malicious script(very possible as we may insert scripts in comments in which friendsterteam is'nt aware) the best solution is to go to ur settings , turn on safe mode , then delete the comment ... that's it .. :thumbsup: somebody gave me a comment with an infinite alert .. stupid noob .. :wallbash: i already got rid of it anyway .. :lol: view my comment page . :D
lollipop_gila
» FTalkAddict
FTalk Level: zero
565
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

I see :lol: thx f0r sharing :thumbsup:
mabuhay
» FTalkManiac
FTalk Level: zero
849
0
1969-12-31

Re: [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

[quote][b]darylldelfin wrote:[/b] woaw .. :o tnx 4 d repu rockmate!! :wow: @topic : well if somebody gave u a comment with a malicious script(very possible as we may insert scripts in comments in which friendsterteam is'nt aware) the best solution is to go to ur settings , turn on safe mode , then delete the comment ... that's it .. :thumbsup: somebody gave me a comment with an infinite alert .. stupid noob .. :wallbash: i already got rid of it anyway .. :lol: view my comment page . :D[/quote] welcum rockmate... thanks again 2 November 4 da info... =):thumbsup:
  • ARCHIVES 
  • » [color=blue][b]Description:[/b][/color] Actually our current js linker, especially the one on the current generator has a security hole that makes people be able put some kinda malicious script by ins

Pages: 12

Board footer

© 2024 F Talk

Current time is 11:13

[ 9 queries - 0.015 second ]
Privacy Policy