RSS Forums RSS
Please support our DaniWeb Community Feedback advertiser: Programming Forums
Views: 3023 | Replies: 37
Reply
Join Date: Apr 2005
Location: Dundee, Scotland
Posts: 13,441
Reputation: jbennet is just really nice jbennet is just really nice jbennet is just really nice jbennet is just really nice 
Rep Power: 33
Solved Threads: 333
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #11  
Jul 29th, 2007
Obviosuly not. This was 1 min ago
Attached Images
File Type: jpg ad.JPG (158.2 KB, 13 views)
TRY MY SUGGESTIONS AT YOUR OWN RISK

Master of puppets Im pulling your strings, blinded by me, you cant see a thing. Master! Master!
Reply With Quote  
Join Date: Apr 2006
Location: Canada
Posts: 4,556
Reputation: John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all 
Rep Power: 17
Solved Threads: 284
Moderator
Featured Blogger
John A's Avatar
John A John A is offline Offline
Vampirical Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #12  
Jul 29th, 2007
Originally Posted by The Dude View Post
OK your using Opera that might explain it....
It happened to me on both Firefox 2 and Safari 3 Beta.

Maybe Opera still executes the script locally instead of from the site?? (Im telling you 'HTML' is disabled on this site!!)

<a href="http://www.daniweb.com/forums">See what i mean?</a>

Now is that formatted correctly for you?? (It shouldnt be if it is)
The Dude, HTML is not disabled on this site. How do you think this site is displayed, then. Flash? LOL.

What happens is the BBCode parser automatically turns '<' and '>' into their HTML character equivalents, &lt; and &gt; while turning [url][/url] into actual HTML code. I suspect a slightly different parser is used for the thread preview window, because it's only plaintext. When that parser was written, the '<' and '>' parsing was probably omitted, creating the bug that Matt so nicely pointed out.

But back on topic, the bug seems to be fixed, thank you Dani!
tuxation.com - Linux articles, tutorials, and discussions
Reply With Quote  
Join Date: Apr 2005
Location: Dundee, Scotland
Posts: 13,441
Reputation: jbennet is just really nice jbennet is just really nice jbennet is just really nice jbennet is just really nice 
Rep Power: 33
Solved Threads: 333
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #13  
Jul 29th, 2007
Its not fixed obviously as im using IE7 and had the bug an hour ago hence the post above
TRY MY SUGGESTIONS AT YOUR OWN RISK

Master of puppets Im pulling your strings, blinded by me, you cant see a thing. Master! Master!
Reply With Quote  
Join Date: Dec 2005
Posts: 2,857
Reputation: The Dude is an unknown quantity at this point 
Rep Power: 8
Solved Threads: 23
The Dude's Avatar
The Dude The Dude is offline Offline
Posting Maven

Re: Message preview seems to allow unfiltered markup... XSS?

  #14  
Jul 30th, 2007
Well it doesnt happen when i enable everything and try it......
Reply With Quote  
Join Date: Apr 2006
Location: Canada
Posts: 4,556
Reputation: John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all 
Rep Power: 17
Solved Threads: 284
Moderator
Featured Blogger
John A's Avatar
John A John A is offline Offline
Vampirical Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #15  
Jul 30th, 2007
Originally Posted by jbennet View Post
Its not fixed obviously as im using IE7 and had the bug an hour ago hence the post above
Could your browser have been caching some files, perhaps?

Originally Posted by The Dude View Post
Well it doesnt happen when i enable everything and try it......

Well... you're the only person that has said you didn't get any popup. So the only thing I can assume is that you were using a crappy web browser.
tuxation.com - Linux articles, tutorials, and discussions
Reply With Quote  
Join Date: Jan 2007
Location: India
Posts: 193
Reputation: shouvik.d is an unknown quantity at this point 
Rep Power: 2
Solved Threads: 6
shouvik.d's Avatar
shouvik.d shouvik.d is offline Offline
Junior Poster

Re: Message preview seems to allow unfiltered markup... XSS?

  #16  
Jul 30th, 2007
Originally Posted by WolfPack View Post
Yes. A Hello World Dialog box pops up when you hover the mouse over this thread listing the the Feedback forum page.

Actually it does not. HTML is disabled
Regards
Shouvik
Reply With Quote  
Join Date: Apr 2005
Location: Dundee, Scotland
Posts: 13,441
Reputation: jbennet is just really nice jbennet is just really nice jbennet is just really nice jbennet is just really nice 
Rep Power: 33
Solved Threads: 333
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #17  
Jul 30th, 2007
Originally Posted by joeprogrammer View Post
Could your browser have been caching some files, perhaps?


Dont think so. Id only just cleared that all out as a matter of fact (haad some spyware)
TRY MY SUGGESTIONS AT YOUR OWN RISK

Master of puppets Im pulling your strings, blinded by me, you cant see a thing. Master! Master!
Reply With Quote  
Join Date: Jan 2007
Location: India
Posts: 193
Reputation: shouvik.d is an unknown quantity at this point 
Rep Power: 2
Solved Threads: 6
shouvik.d's Avatar
shouvik.d shouvik.d is offline Offline
Junior Poster

Re: Message preview seems to allow unfiltered markup... XSS?

  #18  
Jul 30th, 2007
Originally Posted by jbennet View Post
Obviosuly not. This was 1 min ago


Mine to 60 seconds ago
Attached Images
File Type: jpg error.JPG (161.5 KB, 16 views)
Regards
Shouvik
Reply With Quote  
Join Date: Dec 2005
Posts: 2,857
Reputation: The Dude is an unknown quantity at this point 
Rep Power: 8
Solved Threads: 23
The Dude's Avatar
The Dude The Dude is offline Offline
Posting Maven

Re: Message preview seems to allow unfiltered markup... XSS?

  #19  
Jul 31st, 2007
Originally Posted by joeprogrammer
Well... you're the only person that has said you didn't get any popup. So the only thing I can assume is that you were using a crappy web browser.
Your mistaken...my browser is responding like its supposed to...

HTML code is DISABLED on posts on this site,so it doesnt recognize the CODE itself and execute it.....
Last edited by The Dude : Jul 31st, 2007 at 1:18 am.
Reply With Quote  
Join Date: Apr 2006
Location: Canada
Posts: 4,556
Reputation: John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all 
Rep Power: 17
Solved Threads: 284
Moderator
Featured Blogger
John A's Avatar
John A John A is offline Offline
Vampirical Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #20  
Jul 31st, 2007
Originally Posted by jbennet View Post
Dont think so. Id only just cleared that all out as a matter of fact (haad some spyware)

That sounds really odd, is the popup still happening for you right now?
Originally Posted by The Dude View Post
Your mistaken...my browser is responding like its supposed to...
Your browser is supposed to execute HTML code. The BBCode parser is supposed to escape '<' and '>' (as well as a few other characters like quotes, I think...)

Originally Posted by The Dude View Post
HTML code is DISABLED on posts on this site,so it doesnt recognize the CODE itself and execute it.....
You have no idea what you're talking about, and I think this discussion is going in circles. To prove my point, look at the source code on this page of the following two lines:
Google
<a href="http://www.google.com">Google</a>

It should look something like the following:
<a rel="nofollow" href="http://www.google.com" target="_blank">Google</a><br />
&lt;a href=&quot;http://www.google.com&quot;&gt;Google&lt;/a&gt;<br />

HTML isn't disabled, it's just that the BBCode parser escapes it, as you can see (&gt; &lt; &quot;)
Originally Posted by shouvik.d View Post
Mine to 60 seconds ago

Duh. Dani fixed the bug. jbennet so far is the only one that has reported getting the popup window after Dani said she fixed it.
Last edited by John A : Jul 31st, 2007 at 2:05 am.
tuxation.com - Linux articles, tutorials, and discussions
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

Thread Tools Display Modes
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 7:01 am.
Newsletter Archive - Sitemap - Privacy Statement - Acceptable Use Policy - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC