Board index   FAQ   Search  
Register  Login
Board index php forum :: PHP and MySQL Security PHP & MySQL Security

Understanding XSS attacks ...

Security issues related to php and mysql usage. How to make your code secure? Security measures and configurations? It's all in here!

Moderators: macek, egami, gesf

Understanding XSS attacks ...

Postby pepelepew1962 » Wed Jan 25, 2012 7:58 pm

Hello:

I am really trying to understand XSS attacks and can't seem to wrap my head around it, I would rather seem like a fool than program like one with holes in it. My problem is understanding how an attack occurs. Let's say Mary logs into the system and creates a record in the table via an html form. I have php filters and validation for the data before it actually goes into mysql table. My question is how does John attack my website? Or more important, how does he actually change files? If he were to have a log in
and gains access because it doesn't take much to register, how? Is it a matter of the filter being bad and his XSS scipt is in a record and when someone open/views that record (field) the script is launched? I have read lots on how the javascript, for example, is placed in the url or form fields but nothing explains whether the information is saved and launched via the record stored in the database.
pepelepew1962
New php-forum User
New php-forum User
 
Posts: 9
Joined: Sat May 28, 2011 5:12 pm

Re: Understanding XSS attacks ...

Postby TheProdigyGuy » Thu Jan 26, 2012 12:25 pm

Hello
Here is very usefull sites and you can find more information there about XSS(another vulnerabilities as well)
http://www.exploit-db.com/
www.packetstormsecurity.com
http://en.wikipedia.org/wiki/Cross-site_scripting
Just search for XSS,Cross Site Scripting and you can find papers about it.

It is so simple: XSS is Client side Vulnerability(actually it is nothing does on server side)
But when that XSS 'payload' goes to client browser it will exploit.

In ex: Can steal User cookies and using that stealed cookies login to your administration pane without login + password)(You can find a lot of tonnes whitepapers 'how to learn hack')
In ex: Can redirect to malware sites which will try to exploitate client side vulnerabilities(in ex: Drive BY Download,Buffer Overflow in PDF readers,etc)
XSS+SQL injections are common vulnerabilities in web applications.
XSS-is not so harmfull in this case(But it depends on situation)
SQLI is more harmfull.And Serious.

My question is how does John attack my website? Or more important, how does he actually change files? If he were to have a log in

Well,John can find another type vulnerability or misconfiguration on your site.
In ex: Remote file Include,Local File include,Travelsal,SQLi,CSRF etc etc etc.
I will recommend to check all your Access and error logs for such suspic actions.(Log based investigation)
ssh>zgrep 'suspic goes here' *.gz|less

If you can't find anything well you need make sure your hosting is UP2DATE+correctly administering)
BTW,
I would rather seem like a fool than program like one with holes in it

Acunetix is very usefull in this case)
TheProdigyGuy
New php-forum User
New php-forum User
 
Posts: 215
Joined: Wed Dec 07, 2011 5:25 pm

cheapest Herve Leger on sale (12)

Postby griffis99 » Tue May 14, 2013 6:39 am

Are you already utilizing mailing services to send your marketing mails and materials to your target audience? If the answer is no, it is a must for you to know and understand why you should employ mailing services now for your business.
Indeed, there are several remarkable benefits to experience herve leger red when acquiring these services, from commencing your direct mail marketing venture to establishing great customer rapport. Read on and know why this is so. Firstly, getting professional mailing services is a proven technique towards reaching out to possible regular clients straightforwardly. It is probably unwise to be dependent on the postal service of the government because your mails might not reach your audience in an instant. Moreover, you are not assured of the accurate arrival time of your mailers.
Indeed, getting these services will work to your advantage because it herve leger online also helps you cover your intended market at once. By sending out your postcards and other marketing collaterals, you get to reach the proper clients directly. Apparently, you build consistent customer herve leger long sleeve dress relations with this strategy. In addition, you are guaranteed of sustaining the fidelity of your consumers as well as winning new clients. Another advantage of acquiring mailing services is that you get to broaden your coverage and existence to more extensive locations. Apart from your ads over the Net or on TV, you also get to advertise directly to the mailbox of your target clients. Your mailers can also be seen on doorsteps and porches. Indeed, widening and continuing your exposure will help you reiterate your message to your audience.
Moreover, if you continuously carry out your direct mailing activity, the steady stream of your promotional materials and messages will eventually convince your prospective clients to trust your business and react to your mails affirmatively. When you send them your herve leger style dresses materials repeatedly, you create that strong persuasion power over your clients that will make them support your product in the long run.
Last but not the least, using this will serve as your ultimate tool in accurately targeting your desired market for a certain campaign. For instance, if your campaign aims at a certain population, employing it alongside your marketing collaterals will make you benefit from this precision.
You will be able to quickly and conveniently send out your mails to your target audience as long as you have the right addresses and locations of the latter. The good thing is herve leger gold dress you are no longer marketing to a general audience. Your mails shall now be directed to the right people who will positively act in response herve leger replica dresses to it. As a result, you generate more profits.
Nevertheless, undertaking such services also entails obtaining a remarkable mailing list. Before you choose the right company that provides mailing list services, it is noteworthy to determine the type of services you precisely need and the output you aim to achieve. Those offering expensive services generally offer a wide assortment of services and a programmed address list. Be it traditional or electronic, businesses will surely benefit from these. The latter will provide anyone with great chances of successfully managing his/her own business. Now that you know the benefits of acquiring this, it might be the right time to try it now.

Related articles:


cheapest Herve Leger on sale (8)
griffis99
New php-forum User
New php-forum User
 
Posts: 40
Joined: Mon Dec 17, 2012 12:41 am


Return to PHP & MySQL Security

Who is online

Users browsing this forum: No registered users and 1 guest

Sponsored by Sitebuilder Web hosting and Traduzioni Italiano Rumeno and antispam for cPanel.