There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
Site Comments & Suggestions
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Community > Site Comments & Suggestions >
Javascript junk


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 01:24 PM #1
Ok!
I'm about to put a neat little thing into my sig using the vbcode for url. lol.
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 01:26 PM #2
Aww it doesnt work in a sig. Oh well here it is.
EDIT
Doesnt work in a link here at all because of JS blocking. Paste this into the IE address bar to view MD5 Hash of your TSG Password. You must be on a TSG page and logged in at the time.
Ugh the PHP tag is adding a space! at the beginning, change java script to javascript with no space.
PHP Code:
javascript:var cookie=document.cookie;var password cookie.split('bbpassword=');fullpass password[1].split(';');alert(fullpass[0]) 
__________________
-Brendan
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 01:38 PM #3
Boy, wasn't that useful... and on-topic...

But it's nice to see that the javascript blocking works...
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 01:42 PM #4
HAHA I busted your scheme simply by using the W3C reccommendations :P
<a href="#" onclick="var cookie=document.cookie;var password = cookie.split('bbpassword=');fullpass = password[1].split(';');alert(fullpass[0])">Click</a>
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 01:49 PM #5
I hate when things get so far off-topic... I just split this off to another thread.

Nice going... I don't think that's so bad, at least. I'd just hate to have to go to the "no HTML" rule that most forums have due to such misuse.
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 01:59 PM #6
Ok. Is this considered misuse? I will remove it if it is. It in no way reveals the person's password as only they can see the hash, and still there is no possible way to decrypt this hash.
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 02:03 PM #7
Nah, it doesn't bother me at all -- and I think the passwords are pretty secure. But, you can see how such a thing could easily be mis-used by someone, although I'd expect it to be more of an annoyance than a security issue.
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 02:11 PM #8
Hmmm hard to see how it could be misused. RSA has a $200,000 award if you can crack one of these.
I suppose it could be used in some sort of brute forcer but that would take server-side scripting to get someones hash, some way to figure out their username, and many, many hours on a home computer.

It is secure. I have no problem telling everyone, my hash is
REMOVED
Maybe I shouldnt, because pasting that into the cookie with my userid might log them into my account. Not sure if it would. I doubt it.
Anyway, I just did this because I am messing with MD5 hashes.

Edit: You can just edit someones hash and userid into a cookie to log into their account, so posting your hash isnt such a good idea
Unfortunately, it doesnt qualify for the 200,000 bucks because its still not translated into the actual password.
__________________
-Brendan

Last edited by brendandonhu : 31-May-2003 02:25 PM.
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 02:26 PM #9
No, no -- you misunderstand my concern. As I said, I feel that it's very secure -- vb has been around for a while and you're correct about MD5.

My concern is with JavaScript -- imagine the nasty scripts you could run on other people's computers -- even if they're only annoying.
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 02:29 PM #10
Yes thats true. I have some experience there
Actually you could gain access to someones account by simply having them click a link (it could probably be done onload, but I dont know) that would set the value of their cookie to a hidden form field and email it to the hacker...Both of my tsg baddies (this and the signature virus) used forms. If anything should be blocked, its forms.
__________________
-Brendan
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 02:30 PM #11
But how could I possibly block forms without blocking HTML? Sure, I could make forms a badword, but what about people talking about them in the Development forum? I suspect that I'll just have to break down and block HTML one of these days...

But, even then, there's nothing preventing you (or, rather, a bad person) from putting a full script on another web page and just linking to it. *sigh*
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 02:34 PM #12
WAAAH. I won't be posting anything harmful, or even annoying (as far as scripts go for the annoying part ).
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 02:38 PM #13
Oh, I don't doubt that -- after your little virus scam, I'm sure that you've learned your lesson.

I really wouldn't expect anything disruptive from any long-term member, to be honest... whether it's javascript or otherwise.

However, if we're going to worry about security enough to block HTML (as most forums do), you'd really have to go futher -- block all links, etc etc... You can never be completely secure. I guess that's what our wonderful Moderators are here for.
brendandonhu's Avatar
Distinguished Member with 15,988 posts.
 
Join Date: Jul 2002
Location: Ann Arbor, MI
Experience: Advanced
31-May-2003, 02:48 PM #14
You are very lucky the ********com people have not hit this forum (yet).
But I would not block links. Thats just over-moderation. Yes, someone COULD post a link to download Klez, but they probably won't.
TechGuy's Avatar
Computer Specs
Administrator with 8,423 posts.
 
Join Date: Feb 1999
Location: Chambersburg, PA
Experience: Advanced
31-May-2003, 02:53 PM #15
Judging from the censoring in your post, I'd guess that they have. But, you're right -- there's no telling what some people might do. We'll just have to rely on our very capable Moderators!!
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:34 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.