Re: [Full-disclosure] Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature

2006-04-01 Thread Siegfried
This is actually what i wanted to say, "that" stripslashes if you prefer, i'm not sure if he wanted to use it to validate the input, or that would be really dumb, but anyway it's really not important at all i leave you to the n3td3v trolls now, have fun, but keep an eye on all advisories :) S

Re: [Full-disclosure] Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature

2006-04-01 Thread Jasper Bryant-Greene
Siegfried wrote: Yes like you said there is no check, because the stripslashes is a joke. And yes this script isn't famous at all, but it was just to show a recent example of an error in the advisory, even if this one is just a detail Stripslashes is not a joke, it's just not designed for what

[Full-disclosure] Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature

2006-04-01 Thread Siegfried
Yes like you said there is no check, because the stripslashes is a joke. And yes this script isn't famous at all, but it was just to show a recent example of an error in the advisory, even if this one is just a detail There are some people who publish really many xss/sql injection advisories, but