![]() |
|
![]() |
|
|
Thread Tools | Display Modes |
|
|
#31 |
|
Programming Guru
![]() ![]() |
Well, plus this is free, no registration required, and unlimited space.
How would a user execute a file they saved? =S @hervens: A home webserver. |
|
|
|
|
|
#32 |
|
Hobbyist Programmer
|
oh ok
|
|
|
|
|
|
#33 | |
|
Programming Guru
![]() ![]() ![]() |
Quote:
__________________
http://jasonpowers.net "There are a thousand hacking at the branches of evil to one who is striking at the root." |
|
|
|
|
|
|
#34 |
|
Hobbyist Programmer
Join Date: Jun 2006
Posts: 137
Rep Power: 0
![]() |
I would run it on my home server... When I get my FreeBSD to work that is.
|
|
|
|
|
|
#35 |
|
Programming Guru
![]() ![]() |
Oh. So you're talking about executing it client side? -.-
|
|
|
|
|
|
#36 |
|
Hobbyist Programmer
Join Date: Jun 2006
Posts: 137
Rep Power: 0
![]() |
I think I posted that in the wrong place lol, sorry...
|
|
|
|
|
|
#37 |
|
Programming Guru
![]() ![]() |
Wah? I wasn't even responding to what you said. In case that's why you said wrong post. Unless you really did post in the wrong place (coincidentally in context).
![]() |
|
|
|
|
|
#38 |
|
Hobbyist Programmer
Join Date: Jun 2006
Posts: 137
Rep Power: 0
![]() |
Sorry I scrolled up to see who you were talking to and then I saw my post and was like shit, its in the wrong place lol...
|
|
|
|
|
|
#39 | |
|
Programming Guru
![]() ![]() ![]() |
Quote:
I go to your site and create a file/script, that contains some malicious code. I save the file then go to your server, specifically to that file through my browser and execute it. I was just curious as to if there were any constraints on contents of files, or execution of saved files... more or less for the prevention of an intrusion/attack. In other words, when a user saves a file at what location is it stored? Can the user get directly to the file and execute it via a browser? Or is the contents stored in a database that is queried when someone wants to view it?
__________________
http://jasonpowers.net "There are a thousand hacking at the branches of evil to one who is striking at the root." |
|
|
|
|
|
|
#40 |
|
Hobbyist Programmer
|
If you choose a filename, you could choose "abadscript.php".
Then if you know the path you would go to http://onlinefileeditor/username/abadscript.php instead of opening it through the actual website. If the server isn't configured to block scripts in user directories it would run the script. etc.
__________________
#programmingforums relay - http://thegupstudio.com/cgi-bin/pforelay.cgi freelance scripts - http://ryanguthrie.com/index.html |
|
|
|
![]() |
| Bookmarks |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|