Author Topic: IMG exploit?  (Read 2364 times)

0 Members and 1 Guest are viewing this topic.

Offline Joe

  • B&
  • x86
  • Hero Member
  • *****
  • Posts: 10319
  • In Soviet Russia, text read you!
    • View Profile
    • Github
IMG exploit?
« on: January 03, 2006, 05:55:06 pm »
« Last Edit: January 03, 2006, 05:57:50 pm by Joe[e2] »
I'd personally do as Joe suggests

You might be right about that, Joe.


Offline Newby

  • x86
  • Hero Member
  • *****
  • Posts: 10877
  • Thrash!
    • View Profile
Re: IMG exploit?
« Reply #1 on: January 03, 2006, 06:57:05 pm »
- Newby
http://www.x86labs.org

Quote
[17:32:45] * xar sets mode: -oooooooooo algorithm ban chris cipher newby stdio TehUser tnarongi|away vursed warz
[17:32:54] * xar sets mode: +o newby
[17:32:58] <xar> new rule
[17:33:02] <xar> me and newby rule all

I'd bet that you're currently bloated like a water ballon on a hot summer's day.

That analogy doesn't even make sense.  Why would a water balloon be especially bloated on a hot summer's day? For your sake, I hope there wasn't too much logic testing on your LSAT. 

Offline Joe

  • B&
  • x86
  • Hero Member
  • *****
  • Posts: 10319
  • In Soviet Russia, text read you!
    • View Profile
    • Github
Re: IMG exploit?
« Reply #2 on: May 08, 2006, 05:55:23 pm »
[img]http://www.javaop.com/blah.jpg"><!--[/img]

[url=http://www.javaop.com">hm<!--]hm[/url]



Was wondering how it translated a BBCode IMG tag into a HTML IMG tag.
I'd personally do as Joe suggests

You might be right about that, Joe.


Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: IMG exploit?
« Reply #3 on: May 09, 2006, 08:14:41 am »
[img]http://www.javaop.com/blah.jpg"><!--[/img]

[url=http://www.javaop.com">hm<!--]hm[/url]



Was wondering how it translated a BBCode IMG tag into a HTML IMG tag.

By filtering out special characters like ", >, and <, replacing them with &quot;, &gt;, and &lt;.