3 ms·
Escape < and > (and everything else), and check the site for XSS. I don't mean to be rude, and I realize you two coded this up in a really short amount of time
by Xk 16y ago
Escape < and > (and everything else), and check the site for XSS. I don't mean to be rude, and I realize you two coded this up in a really short amount of time -- but before this site goes live it would be best to have it secure.
Demo: http://profile.io/foobar http://profile.io/foobar
[EDIT] As someone else pointed out, viewing the list-of-developers page puts up the XSS, which is even worse. I didn't know that page existed.
[EDIT2] It turns out I broke a lot more than I tried to. I also own the account 'xss' which has an unclosed '<' inside of its name, and that destroys half the page. I'm really sorry, please delete that account.
[EDIT3] I broke that account even more in order to fix it. I had an unclosed script tag, so I closed it off in my 'location'. If you fix the xss in just the profile information, then the page will get messed up again.
[EDIT4] The 'test' account was deleted, but the XSS's haven't been fixed? Updated to point to a different page I had made.
- dannyr 16y agoFixed. Let me know if we missed anything. I wish we could use Django's autoescape filter but App Engine's SDK ships with just 0.96 by default. We can only upgrade to a later version of Django in Prod and not locally.
- Xk 16y agoUsernames aren't sanitized yet. (As is visible with the '<asdf' in the 'foobar' link above.) EG: http://profile.io/xss2 http://profile.io/xss2
- qeorge 16y agoAlso, you missed the login form (both in the header and on http://profile.io/login http://profile.io/login). Its echoing the username directly, e.g., "Username <script>alert(1)</script> was not found"
- StavrosK 16y agoYou really need to use Django-nonrel, it's at 1.3b and awesome. I use it for http://www.yourpane.com http://www.yourpane.com and it works fantastically well.
- ddemchuk 16y agohttp://www.youtube.com/watch?v=hzVJFv9GyJg http://www.youtube.com/watch?v=hzVJFv9GyJg Seriously though, I hope you realized that the best thing to do when someone has XSS issues is to just tell them rather than EXPLOIT them.
- Xk 16y agoUpvoted because that's a valid point, but I did consider it before just doing that. I knew the developers of the site were looking here. I knew there was nothing critical running on this site. They were asking for feedback. Given that, it is much easier to demonstrate the places where it should be fixed than to give instructions on how to recreate each attack.
- Locke1689 16y agoTesting for exploits usually requires you to actually try an exploit. Edit: just to be clear, this is for black box testing.