|
|
|||||||||
|
|||||||||
|
|||||||||
| |
||
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#16
|
||||
|
||||
|
Quote:
![]() |
|
#17
|
|||
|
|||
|
Quote:
Thanks, Since I still can't PM (need 4 more posts after this one), Is it ok to ask you a question here, like, my dad's site is www.fgsgems.com, and i'm testing it for vulnerabilities, and how would the hacker manipulate the hidden fields? Like how would they inject it into the form? |
|
#18
|
||||
|
||||
|
check the inbox again...
![]() |
|
#19
|
|||
|
|||
|
Quote:
Ugh, I'm sorry if I am not understanding this, But How does the hacker input information into those hidden fields, like, I know how to view them (view source, correct?) but how does a hacker input the changed values into the fields? *EDIT* ok, I guess my dad's site is all right against this vulnerability, because he does not store the prices in a hidden field... ugh, I'm aggrivated because I am still confused ![]() |
|
#20
|
||||
|
||||
|
I'll construct example when I'll have more time.. remind me within couple of days
hopefully until then you'll have the 10 posts... ![]() |
|
#21
|
|||
|
|||
|
Quote:
haha thanks! I really appreciate it. I definately will, Thanks for all your help and stuff. -alex |
|
#22
|
||||
|
||||
|
Quote:
A hacker would do the following... 1) View the source and determine if there was a hidden field storing the price of the item. 2) They would the save the source to their computer. 3) Change the value of the hidden field. 4) Change the forms action attribute to correspond to the website path the form would submit to. |
![]() |
| Viewing: ASP Free Forums > Web Design > Site Reviews > Www.acotis.co.uk |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|