Monday, 19 March 2007
06:44:49 PM (GMT)
and images (works in IE 6). Trust me on this Hina, blacklisting is _not_ the way to
Okay, as for the other vulns. To get someone off the fleeting thoughts. I noticed
that when someone has questions, the box does not come up. What possible things could
I do to make sure they cannot answer the questions? Also, as for the front-page
thing, that uses the same method as before. What I am about to do may shed some light
on the matter.
Okay, so I showed off a bit there. It probably wont show up properly in your
browser/resolution combo, but hopefully you'll see what I mean. If it's worked
correctly, you probably wont notice a thing different. Click on the 'home' link, and
it'll take you to google. It probably will be out of place though, I'd have to do my
research if I wanted it properly crossbrowser/resolution. I also had to use
what I did to the 'edit character' box (but only in IE6).
Anyway, back to the other exploits. I figure I'm gonna fully disclose, most people
wont know what I'm going on about anyway. Basically I use CSS to make a 100% width
100% height white backgrounded box, and send that in a comment (to kill the entry and
with it the 'delete comments' button), or a question (they wont be able to answer,
and thus will be banished from the fleeting thoughts), or whatever.
Last edited: 19 March 2007