3 ms·
In my experience the vast majority of the time exploits are found over Ajax APIs. Developers just forget that sanitization client side isn't secure. It's a good
by Ralo 4y ago
In my experience the vast majority of the time exploits are found over Ajax APIs. Developers just forget that sanitization client side isn't secure. It's a good party trick for sure.
- LoganDark 4y agoThe funny thing is that you actually didn't do it by searching for an actual space—you would search for an underscore, and they would convert it to a space after checking if the input is empty, but before trimming, so...