3 ms·
I don't think this is anything dangerous. All the data is static, its just some sort of demo. It doesn't matter who goes to the page, they will always get the
by fred10 15y ago
I don't think this is anything dangerous. All the data is static, its just some sort of demo. It doesn't matter who goes to the page, they will always get the same data, it never changes. I'm not a customer so can't try once logged in. If I was to wildly speculate, I'd say honeypot.
- djwelch666 15y agoThis is dangerous! Someone has left the debug=true in the config somewhere. Anything could be possible on the site, not just the script injection in the url and the debug page, but a lot of other stuff as well. When the debug flag is true on our sites, we have a link which will authenticate us as an admin without any credentials for example!
- rufibarbatus 15y ago> When the debug flag is true on our sites, we have a link which will authenticate us as an admin without any credentials for example! Well, get rid of that and push for a change in your company's workflow. This kind of control shouldn't be deployable to the main servers at all. Have separate, staging servers and run your tests and debugging interfaces on it, but as much as possible, don't deploy administrator interfaces to the servers that talk to the customer. [1] [1] I'm undecided which kinds of heisenbugs would justify breaking that lemma.
- phpnode 15y agohuge glaring XSS vulnerability on a credit card company's homepage is not serious? This kind of stuff is a phisher's dream