Re: Security Advisory for ALL forum services with client-set images

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



James Bandara wrote/schrieb/scripsit:
To block this I suggest you edit your service to only accept links that end in image formats for images before the querystring.

That doesn't really help â the attacker can send a HTTP redirect from an innocent-looking URL.


-Stefan
--
junior guru   SP666-RIPE     JID:stefanp@xxxxxxxxxxxxxxxx    SMP@IRC

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux