Unless it's attached to a kitten.
1st post!
From the 100% Fact challenge. See all 469 entries (closed)
(, Tue 28 Oct 2003, 16:57, archived)
FACT: 'Scientists are currently developing "cat butter" which self-rights falling toast'
welcome!
(, Tue 28 Oct 2003, 16:59, archived)
'I am also the one that started the chain of events leading to the banning of javascript from profiles. Sorry... '
damn
(, Tue 28 Oct 2003, 17:00, archived)
it turned out by a clever combination of javascript document.write commands, you could pass usernames and passwords to a logging script on your server, such as PHP.
(, Tue 28 Oct 2003, 17:01, archived)
i thought you would have done something less serious like making annoying dialog boxes come up
(, Tue 28 Oct 2003, 17:02, archived)
it was tef who discovered unencrypted passwords could be logged.
(, Tue 28 Oct 2003, 17:03, archived)
I discovered it some time before but did the sensible thing and mailed Rob rather than making it common knowledge. So ner.
(, Tue 28 Oct 2003, 17:09, archived)
the response I got was, "Cheers - I'll forward it to Cal. He'll probably put a patch in place in a few days."
I suppose it wasn't much of a priority while nobody knew about it, which is the good thing about it going public :)
(, Tue 28 Oct 2003, 17:20, archived)
with his nasty show your username and password when you see his profile, malarky
(, Tue 28 Oct 2003, 17:01, archived)
i made a nice use of scripts, he changed it a bit and got nasty.
(, Tue 28 Oct 2003, 17:03, archived)
I still blame him, but as I've never got the hang of javascript, it's not been much of a burden
(, Tue 28 Oct 2003, 17:07, archived)
That wouldn't suprise me!!
Tef scares me when he starts telling me my passwords (I trust him enough not to do anything with them, but it seems worryingly easy)
(, Tue 28 Oct 2003, 17:04, archived)
i know that....I've been having a little play with b3ta myself (in the most friendly way possible)
My university dissertation is to research into, write up and create a secure website....
(, Tue 28 Oct 2003, 17:11, archived)