Jump to content
MakeWebGames

Recommended Posts

Posted

well its pretty much the same as the avatar attack u can put a php script in between the and or <img> and </img> and put it in their profile or post it in a forum and it will run the script each time the thread/profile is viewed how should we go about fixing this?

if this has already been mentioned please direct me to a topic that will help me fix this

Posted

mysql_real_escape_string the spot where they Input the Data

Then the place that the data is Output htmlentities.

Secure your scripts and shouldnt have a prob :D

Also if you have MTG's Forums they already stop that as the output is secured.

Gl

Posted

lol didn't i post on this about 2 weeks ago... This is old depends on your definition of image hacking really i guess.

I did comment on how easily display image is to hack even way more advanced that this method:) im sure you will be enlightened by it.

link : Exploits

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...