📜 ⬆️ ⬇️

The Return of the Black Lord?

This is what happens if you do not clean up the HTML and the escaping of special characters.

To developers of a habr - a shame! The site has been working for more than one year, but so far they have not normally done a safe conclusion of content! No screen adaptation of the characters, or cleaning HTML from "harmful impurities"!

It’s good that guys like Satana are crazy about drawing attention to the problem. But everything can be more serious. I would not be surprised if it soon becomes clear that some cunning guys have long been quietly exploiting various vulnerabilities of the habr to a wide audience. For example, they build botnets of us.
')
Sorry for the sharpness, but it is - disrespect visitors. So you can lose confidence in the site.

PS To justify the fact that "a new version will be released soon" is stupid. Imagine if Micrsoft would stop releasing critical updates to Windows XP, arguing that "Vista will be out soon" ?! Maybe it will, but all sorts of "Kul Hackers" exploit Habr right here and right now. Are you sure that your browser does not have any vulnerabilities? Me not. Although I use the latest Firefox in Ubunt and put all the updates.

Upd: Anyone who believes that about a botnet, I exaggerate, I advise you to type in the phrase "Internet Explorer CSS vulnerable" in Google. Here, for example, is a Microsoft CSS CSS vulnerability tag (MS07-033) Tag Memory Corruption Vulnerability from 06/12/2007, with a remarkable description of “Microsoft Internet Explorer vulnerability in Microsoft Internet Explorer”. "In Google there is a lot more of this kind, try replacing" CSS "with" PNG "," GIF "," JavaScript "and all sorts of other buzz words :) I hope everyone has a licensed Windows with all the updates? ;)

Source: https://habr.com/ru/post/22984/


All Articles