TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Another Security Hole Found On Yelp, Facebook Data Once Again Put At Risk

38 点作者 whyleym大约 15 年前

3 条评论

gdeglin大约 15 年前
If anyone is curious, these security holes were found in dynamically generated javascript that included a GET parameter that was neither encoded nor run through magic_quotes. They were easy to find to the point where an automated scanning tool could almost certainly identify them.
评论 #1340488 未加载
DCoder大约 15 年前
Well, at least they had to <i>try</i> to find a hole. I've had the pleasure of maintaining a "typical PHP project" - written by someone with no clue about xss, csrf or anything else. It had an admin interface that simply returned the Location: / header to an unauthorized user without exiting. In a publicly accessible /admin folder no less. The owner only wisened up when Yahoo's spider crawled in and followed all the "delete news item" links. Yes, GET links for delete, and DB storing passwords in plain text, isn't that nice.
farmer_ted大约 15 年前
Is anyone still using Facebook?