  | 
        
  | 
   
 
    
        
      
          | 
  
  
  
    
    
        
	  | 
	Menu | 
	  | 
 
 
    
     
     
     
      
       
       
        
         
         
          
           
						 |  
						 Home |  
 |   |  
						 |  
						 Discussions |  
 |   |  
						 |  
						 Tools |  
 |   |  
						 |  
						 Affiliates |  
 |   |  
						 |  
						 Content |  
 |   |  
						 |  
						 Info |  
 |   |    | 
            
          
         | 
       
     
    | 
    
   
   | 
   
 
 | 
   
 
  
    
    
        
	  | 
	User Info | 
	  | 
 
 
    
     
     
     
      
       
       
        
         
         
          
             Membership: 
  Latest: MichaelSnaRe 
  New Today: 0 
  New Yesterday: 0 
  Overall: 9144 
 
  People Online:
 
  Visitors: 122 
  Members: 0 
  Total: 122 
 | 
            
          
         | 
       
     
    | 
    
   
   | 
   
 
 | 
   
 
  
    
    
        
	  | 
	Full disclosure | 
	  | 
 
 
    
 | 
   
 
 | 
  
    
        
	  | 
	 | 
	  | 
 
 
    
        
          
              
                
                    
                      
                          
                            
                            
	
	
		  | 
		 | 
	 
	
		  | 
		IT Security and Insecurity Portal | 
	 
	 
	 | 
 
 
 
	
	
		 Forum:Fun corner Posted: Tue Sep 02, 2008 9:20 pm Subject: :) | 
		 | 
	   | 
 
	
	
		
 
  | 
		
		
			ahahhaahahh 
 http://www.yourdailymedia.com/media/1220270903/Hilarious_Frozen_Lake_Dive | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			And nice way finding neighboors:)))
 
 http://gagspace.com/ip2vhost/
 http://www.dnsdigger.com/ | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			| Can httpOnly cookie protection be defeated or it is the end of XSS:) | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			| Yes but in the advisory it says its only fo PHP 5.So i asked whats the difference for php 4 if there is any?? | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			Looking at the folowing exploit : http://securityreason.com/securityalert/2831
  i created following .htaccess file
 php_value mail.force_extra_parameters -t&&cat /etc/passwd but im sure im go ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			Whats wrong with the following code
 
 Query1->Close();
 Query1->SQL->Clear();
 Query1->SQL->Add("select number from calls where number like :test ");
 Query1->Params->Items[0]-&g ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			| Can someone clarify XSS using POST method.Thanks | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			I don't know if php was compiled with mssql support anyway here is nice java script that has done the job perfectly
 
 <%@ page contentType="text/html; charset=windows-1255" language="java" import= ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			Ok the problem was that sending direct of xss site to someones mail is not working but sending simple redirect page is working like a charm:D
 <?php
   header("Location: http://msn-xss site
   exit ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			| Some error ocured  Call to a member function on a non-object at this line $conn->open($connStr) | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			Is there any perl or php script to access mssql.
 
 Following methods seems not to work:
 use DBI;
 my $DSN = 'driver={SQL 
 Server};Server=node.domain.com;database=my_database;uid=username;
          ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			| Unless your browser has scripting disabled, you should be returned to the page you were at in a couple seconds. Otherwise, please click here to return manually. | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
 
  | 
		
		
			$passwd = md5(md5($passwd) . $SALT) i think this is the correct form for vbulletin
 
 md5(md5($salt).md5($pass)) is for invision boards
 
 Anyway very nice idea:D | 
		 
		  | 
	 
	  | 
 
 
  
	| Page 1 of 4 | 
	Goto page 1, 2, 3, 4Next All times are GMT | 
   
 
  
Powered by phpBB © 2001-2008 phpBB Group
 
  
 
 
 | 
                           
                         
                         | 
                     
                    | 
               
              | 
         
       
       | 
   
  | 
 
 
 |