Journaling on estrip is free and easy. get started today

Last Visit 2024-03-16 17:05:41 |Start Date 2003-07-07 03:39:31 |Comments 5,617 |Entries 6,438 |Images 14,748 |Sounds 119 |SWF 21 |Videos 322 |Mobl 2,935 |Theme |

Category: html

05/15/15 02:26 - ID#59991

The Ugliest HTML

This vendor is so terrible.

image

Its not just this, its everything.

At one point I found their image loader just let me load any file on their server something like <img src="imageloader.asp?path=c:\inetpub\somefolder\some.jpg" /> which was easily replaced with any file on the server in order to stream it.

When I discussed it with their security team they changed it to something like <img src="imageloader.asp?path=HKJSHD*IY#(#:DJGT..." /> but every image still starts with the same prefix leading me to believe that is the representation of c:\ etc in whatever lame homegrown encryption method they tried to use.

Its scary that they are in the cloud business storing sensitive information.

print addComment

Permalink: The_Ugliest_HTML.html
Words: 124
Last Modified: 05/15/15 02:26


Search

Chatter

New Site Wide Comments

joe said to joe
Never send a man to do a grandma's job...

sina said to sina
yes thank you!
Well, since 2018 I am living in France, I have finished my second master of science,...

paul said to sina
Nice to hear from you!! Hope everything is going great....

paul said to twisted
Hello from the east coast! It took me so long to see this, it might as well have arrived in a lette...