Where you be? ~ Frappr

Ye' old general discussion board. Basically, for everything that isn't covered elsewhere. Come here to shoot the breeze, shoot your mouth off, or whatever suits your fancy.
This forum is not for asking programming related questions.

Moderator: General Moderators

User avatar
hawleyjr
BeerMod
Posts: 2170
Joined: Tue Jan 13, 2004 4:58 pm
Location: Jax FL & Spokane WA USA

Post by hawleyjr »

method_man wrote:i joined!
Yes, and you have your shirt off :?

lol, j/k
method_man
Forum Contributor
Posts: 257
Joined: Sat Mar 19, 2005 1:38 am

Post by method_man »

haha, only pic i have on my computer
User avatar
neophyte
DevNet Resident
Posts: 1537
Joined: Tue Jan 20, 2004 4:58 pm
Location: Minnesota

Post by neophyte »

Neophyte's onboard! Me and mine, that is...
User avatar
Maugrim_The_Reaper
DevNet Master
Posts: 2704
Joined: Tue Nov 02, 2004 5:43 am
Location: Ireland

Post by Maugrim_The_Reaper »

My first encounter with Frappr is going...suspiciously.

After joining the DevNetwork group, and zooming out the map, clicking on any markers results in two javascript message alerts containing one term - "XSS"...
User avatar
Chris Corbyn
Breakbeat Nuttzer
Posts: 13098
Joined: Wed Mar 24, 2004 7:57 am
Location: Melbourne, Australia

Post by Chris Corbyn »

Maugrim_The_Reaper wrote:My first encounter with Frappr is going...suspiciously.

After joining the DevNetwork group, and zooming out the map, clicking on any markers results in two javascript message alerts containing one term - "XSS"...
That's timvw, trying to prove that Frappr haven't locked things down. You can insert JavaScript code. Luckily that's just an alert, not a vicious attack. I don't think Frappr seem to care :?
malcolmboston
DevNet Resident
Posts: 1826
Joined: Tue Nov 18, 2003 1:09 pm
Location: Middlesbrough, UK

Post by malcolmboston »

couldnt they just do htmlentities () to circumvent this? i can see no reason for them not doing so, seems perfectly easy to me
User avatar
neophyte
DevNet Resident
Posts: 1537
Joined: Tue Jan 20, 2004 4:58 pm
Location: Minnesota

Post by neophyte »

If JS can be inserted, than probably HTML too. I wonder what would happen if someone inserted a table with a width of say 700px.
User avatar
Maugrim_The_Reaper
DevNet Master
Posts: 2704
Joined: Tue Nov 02, 2004 5:43 am
Location: Ireland

Post by Maugrim_The_Reaper »

Poor form really, all you need is someone to point to on of those evil js files to start a little cookie stealing...

Anyways, I now exist as the sole member from Ireland... My marker looks lonely all by itself...
timvw
DevNet Master
Posts: 4897
Joined: Mon Jan 19, 2004 11:11 pm
Location: Leuven, Belgium

Post by timvw »

Well, while i was editting my profile i accidentally pasted some <b>Warning</b> php message in there... And i was that it was not escaped... So i thought, let's try the first string at the XSS Cheat sheet... I've send them an e-mail last week, got a reply the day before yesterday... But haven't seen any improvements yet...
timvw
DevNet Master
Posts: 4897
Joined: Mon Jan 19, 2004 11:11 pm
Location: Leuven, Belgium

Post by timvw »

Apparently they have made some changes that make the xss trick i did impossible (Too lazy to try other stuff from the cheat sheet) but they forgot to remove it from existing profiles... (I removed it myself today ;p)
User avatar
hawleyjr
BeerMod
Posts: 2170
Joined: Tue Jan 13, 2004 4:58 pm
Location: Jax FL & Spokane WA USA

Post by hawleyjr »

Alright we're up to 49 users!

Who wants to be Devnet Frapper user #50???
User avatar
Burrito
Spockulator
Posts: 4715
Joined: Wed Feb 04, 2004 8:15 pm
Location: Eden, Utah

Post by Burrito »

I used to be on there...so technically we've already had 50.
User avatar
Luke
The Ninja Space Mod
Posts: 6424
Joined: Fri Aug 05, 2005 1:53 pm
Location: Paradise, CA

Post by Luke »

I'm on there... and I'm sexy.
User avatar
RobertGonzalez
Site Administrator
Posts: 14293
Joined: Tue Sep 09, 2003 6:04 pm
Location: Fremont, CA, USA

Post by RobertGonzalez »

Yeah, but I have the cutest picture...
User avatar
Luke
The Ninja Space Mod
Posts: 6424
Joined: Fri Aug 05, 2005 1:53 pm
Location: Paradise, CA

Post by Luke »

I... can't compete with that. :cry:
Post Reply