Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #31204

Re: Javascript injection

From "Christoph M. Becker" <cmbecker69@arcor.de>
Newsgroups comp.lang.javascript
Subject Re: Javascript injection
Date 2016-08-29 11:27 +0200
Organization solani.org
Message-ID <nq0v5u$7j4$1@solani.org> (permalink)
References <2a5cf91a-151b-4379-9510-5dcd5a5bb196@googlegroups.com>

Show all headers | View raw


On 29.08.2016 at 07:58, bit-naughty@hotmail.com wrote:

> If I have a "forum" type of site, where stuff is being posted, and stored in the backend (in a MySQL database, using PHP), say,....can anyone type in Javascript into the post to accomplish naughty things? What's the most nefarious thing anyone can do? All I can think of is that someone would deface the page somehow, that *that* post is on, which, really, I can't see the point of..... Anything else?
> ...and how do I protect against it? (the post will probably be displayed inside a DIV on the page, I think....)

I suggest you read about Cross-Site-Scripting (XSS), for a start.

-- 
Christoph M. Becker

Back to comp.lang.javascript | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Javascript injection bit-naughty@hotmail.com - 2016-08-28 22:58 -0700
  Re: Javascript injection "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-08-29 11:27 +0200
  Re: Javascript injection Hans-Georg Michna <hans-georgNoEmailPlease@michna.com> - 2016-08-29 15:58 +0200
    Re: Javascript injection "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2016-08-29 17:10 +0200
      Re: Javascript injection Aleksandro <aleksandro@gmx.com> - 2016-08-30 16:35 -0300
        Re: Javascript injection "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2016-08-31 10:25 +0200
          Re: Javascript injection "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-08-31 12:43 +0200

csiph-web