• Home
  • Index
  • Search
  • Download
  • Server Rules
  • House Roleplay Laws
  • Player Utilities
  • Player Help
  • Forum Utilities
  • Returning Player?
  • Toggle Sidebar
Interactive Nav-Map
Tutorials
New Wiki
ID reference
Restart reference
Players Online
Player Activity
Faction Activity
Player Base Status
Discord Help Channel
DarkStat
Server public configs
POB Administration
Missing Powerplant
Stuck in Connecticut
Account Banned
Lost Ship/Account
POB Restoration
Disconnected
Member List
Forum Stats
Show Team
View New Posts
View Today's Posts
Calendar
Help
Archive Mode




Hi there Guest,  
Existing user?   Sign in    Create account
Login
Username:
Password: Lost Password?
 
  Discovery Gaming Community The Community Real Life Discussion
« Previous 1 … 32 33 34 35 36 … 246 Next »
[Rant] Forum safety in general.

Server Time (24h)

Players Online

Active Events - Scoreboard

Latest activity

[Rant] Forum safety in general.
Offline Error
05-13-2016, 01:10 PM, (This post was last modified: 05-13-2016, 01:37 PM by Error.)
#3
Web Enthusiast
Posts: 1,212
Threads: 40
Joined: Jan 2008
Staff roles:
Coding Developer

Wait, what? I noticed and reported exactly the same issue when [hr=<colour>] was first released on the tenth of March. I'm also quite sure I checked to see that things were still working like they should when it was renamed to [hrc], so this surprises me quite a bit, to say the least; not sure what's happened here, nor why. Input sanitation really isn't that difficult, and particularly not so for an issue that's already been reported and seemingly fixed once.

If you don't mind sharing it: What was the exact input(s) you could use for [hrc=] while it was broken; just regular old "#FFF; <css code goes here>" or straight up ";<css code goes here>"?

Re: Alley: One thing MyBB thankfully has to do is replace most HTML/CSS-related non-alphanumeric characters with their respective HTML entities, which limits the potential for most XSS attacks due to bad (or nonexistent) template input sanitation for posts quite a bit. At least it removes the ability to directly inject inline scripts or otherwise directly modify the DOM on the element level, and XSSTC isn't an issue any more in modern browsers as far as I know. Still pretty bad indeed, though.
  Reply  


Messages In This Thread
[Rant] Forum safety in general. - by Corile - 05-13-2016, 12:01 PM
RE: [Rant] Forum safety in general. - by Alley - 05-13-2016, 12:52 PM
RE: [Rant] Forum safety in general. - by Error - 05-13-2016, 01:10 PM
RE: [Rant] Forum safety in general. - by DragonLancer - 05-13-2016, 01:55 PM
RE: [Rant] Forum safety in general. - by Error - 05-13-2016, 02:01 PM
RE: [Rant] Forum safety in general. - by Corile - 05-13-2016, 01:58 PM
RE: [Rant] Forum safety in general. - by Corile - 05-13-2016, 03:12 PM
RE: [Rant] Forum safety in general. - by Error - 05-13-2016, 05:33 PM
RE: [Rant] Forum safety in general. - by DragonLancer - 05-13-2016, 05:43 PM
RE: [Rant] Forum safety in general. - by Corile - 05-13-2016, 07:55 PM

  • View a Printable Version
  • Subscribe to this thread


Users browsing this thread:
1 Guest(s)



Powered By MyBB, © 2002-2026 MyBB Group. Theme © 2014 iAndrew & DiscoveryGC
  • Contact Us
  •  Lite mode
Linear Mode
Threaded Mode