20096 total geeks with 3178 solutions
Recent challengers:
 Welcome, you are an anonymous user! [register] [login] Get a yourname@osix.net email address 

Articles

GEEK

User's box
Username:
Password:

Forgot password?
New account

Shoutbox
Domuk
No, not an issue with the PHP - I was responding to "AJAX not being cross site is annoying"
MaxMouse
Really? i thought that would only be important if the user had some kind of control over where the XML came from, if you hard code it (As in a PHP file) wouldn't that eliminate XSS attacks?
Domuk
Yes, but very, very necessary. AJAX requests run in the context of the browser, there'd be no security if it was cross-domain .
MaxMouse
AJAX not being cross site is annoying, all other scripts can be used in that way, having to resort to PHP to patch it is a shame.
SAJChurchey
thx MaxMouse

Donate
Donate and help us fund new challenges
Donate!
Due Date: Nov 30
November Goal: $40.00
Gross: $0.00
Net Balance: $0.00
Left to go: $40.00
Contributors


News Feeds
The Register
FDA takes aim at
illegal net
pharmacies
Oman cuffs 212 for
selling VoIP calls
IBM chase HP (and
Sun) with tiny mem
prices
Hackers free Snow
Leopard from
Jobsian cage
MySpace makes peace
with Indies
Nvidia previews
next-gen Fermi GPUs
Potty-mouths
charged for Comcast
hijack
Microsoft
Silverlight - now
with hidden Windows
bias
Apple cult leader
emails outside
world
Sony demos monster
3D TV
Slashdot
New Microsoft
Silverlight
Features Have
Windows Bias
How Heavy Is the
Internet?
Anti-Smoking
Vaccine Is Nearing
the Market
iPhone Owners
Demand To See Apple
Source Code
Proton Beams Sent
Around the LHC
Microsoft"s Lack of
Nightly Builds For
IE
Some Claim Android
App Store Worse
Than iPhone"s
Climatic Research
Unit Hacked, Files
Leaked
Aging Nuclear
Stockpile Good For
Decades To Come
Netbooks Have
Higher Failure Rate
Than Laptops
CoDebug
Posted by CodeX Fri 9th Oct 07:32

001 
002 
003 
Pate this into your URL bar and smash enter, you know you want to...
[code]javascript: alert("CodeX says:\n\"Hello
"+document.cookie.match(/username=(.+?); /)[1]+"!\"\n:3");[/code]

The following amendments have been posted:

  • CodeX (Fri 9th Oct 07:33)


Submit a correction or amendment below. (click here to make a fresh posting)

Author:

Verify:
(Enter the number you can see above.)
Code: To ensure legibility, keep your code lines under 80 characters long.
Include comments to indicate what you need feedback on.


Recent Pastes
CodeX
12 days ago
KingCepheus
31 days ago
CodeX
42 days ago
CodeX
42 days ago

Your Ad Here
 
Copyright Open Source Institute, 2006