Duh!
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Reply to: The Sun Reporting Murdock Dead
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "The Sun Reporting Murdock Dead"
Collapse
-
-
Originally posted by PinkPoshRat View Posthmm, thanks that's got me sold on the idea of what to learn when I start on my new contract. I shall attempt to learn SQL
I know jack about SQL. I hope it fairly easy to learn from CBT stuff?
Actually it's pretty easy to learn to do it well too (from a security standpoint), it's just more work so people don't bother / think about it.
Bounds checking, exception handling, escaping control characters, filtering key words etc is all simple stuff, it just makes the job take longer. Most os that actually gets done on the front end though, rather than at the database SQL level.Last edited by DaveB; 19 July 2011, 13:05.
Leave a comment:
-
I think the Grauniad suggested there was a vulnerability in the Sun's "comment on this article" form, which could have allowed any SQL entered (as opposed to the usual 'i luv katie i think shes fab lol!') to be executed. The implication is that the Sun's web app passed this to the database without checking it first.
Leave a comment:
-
hmm, thanks that's got me sold on the idea of what to learn when I start on my new contract. I shall attempt to learn SQL
I know jack about SQL. I hope it fairly easy to learn from CBT stuff?
Leave a comment:
-
Originally posted by DodgyAgent View PostIt may be unfashionable to think it or say it but anyone who has helped to break the power of the Unions,to question the sanctity of the BBC and socialism in general (and introduce porn to TV)
is OK by me
Leave a comment:
-
It may be unfashionable to think it or say it but anyone who has helped to break the power of the Unions,to question the sanctity of the BBC and socialism in general (and introduce porn to TV)
is OK by me
Leave a comment:
-
An example of cross site scripting would be if we could write <script type="javascript/text">alert('hello');</script> in a post and then when people viewed the thread the javascript was executed. This example would be harmless but it could do far nastier stuff like sending your session information off to someone who could then use it to pretend to be you.
Leave a comment:
-
Originally posted by PinkPoshRat View Postsomeone please try to explain to me what an XSS attack is, in plain English please!
I'm guessing the 'SQL injection' means the database has stuff added to it?
SQL Inject = instead of your name write "SELECT * user_perms;" etc etc to read user info. A badly written website wouldn't escape that and instead of trying to insert your name in a comments form would insert the SQL you had written which the server will duly run.
Leave a comment:
-
Don't worry, I don't know what they're talking about either.
If its got more than 4k of memory and you don't program it in assembler, I start getting panic attacks.
Leave a comment:
-
someone please try to explain to me what an XSS attack is, in plain English please!
I'm guessing the 'SQL injection' means the database has stuff added to it?
I'm loving all of this twice as much as you guys are, not only is this all the best news story ever, but for me to try and understand what you're talking about is good fun too!!
Leave a comment:
-
Originally posted by fullyautomatix View PostIf it was such a complete control of the server/CMS/file system whatever, why didnt they just modify the home page of "Sun" and put the story up there ? Why a redirect? and why not a server side redirect rather than a client redirect ?Last edited by DaveB; 19 July 2011, 11:49.
Leave a comment:
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- How 15% employer NICs will sting the umbrella company market Today 09:16
- Contracting Awards 2024 hails 19 firms as best of the best Yesterday 09:13
- How to answer at interview, ‘What’s your greatest weakness?’ Nov 14 09:59
- Business Asset Disposal Relief changes in April 2025: Q&A Nov 13 09:37
- How debt transfer rules will hit umbrella companies in 2026 Nov 12 09:28
- IT contractor demand floundering despite Autumn Budget 2024 Nov 11 09:30
- An IR35 bill of £19m for National Resources Wales may be just the tip of its iceberg Nov 7 09:20
- Micro-entity accounts: Overview, and how to file with HMRC Nov 6 09:27
- Will HMRC’s 9% interest rate bully you into submission? Nov 5 09:10
- Business Account with ANNA Money Nov 1 15:51
Leave a comment: