<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : Locati&#111;n</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : Locati&#111;n]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Mon, 13 Apr 2026 05:09:47 +0000</pubDate>
  <lastBuildDate>Tue, 07 Jun 2005 09:48:13 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=15373</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[Locati&#111;n : This isn&amp;#039;t really a security...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84744.html#84744</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 07&nbsp;June&nbsp;2005 at 9:48am<br /><br />This isn't really a security whole, in fact I have done it myself using standard Firefox plugins.<br><br>The country drop down doesn't check if the country entered is in thelist as user may change the list or even change it to a text field andlet the users type their own country in.<br><br>Instead to keep security the country that the users enters is runthrough security filters to filter out an malicious code that the usermay try and enter.<br>]]>
   </description>
   <pubDate>Tue, 07 Jun 2005 09:48:13 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84744.html#84744</guid>
  </item> 
  <item>
   <title><![CDATA[Locati&#111;n : One way of doing it is to copy...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84723.html#84723</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=9949">dpyers</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 06&nbsp;June&nbsp;2005 at 10:15pm<br /><br />One way of doing it is to copy source to your pc, make whatever changes tou want to dropdowns, and run the source from your pc.<DIV>&nbsp;</DIV><DIV>Form handlers however should check that the http_referrer they get is from their domain.</DIV>]]>
   </description>
   <pubDate>Mon, 06 Jun 2005 22:15:21 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84723.html#84723</guid>
  </item> 
  <item>
   <title><![CDATA[Locati&#111;n : You would have add a table to...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84710.html#84710</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18731">sfd19</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 06&nbsp;June&nbsp;2005 at 4:47pm<br /><br />You would have add a table to the database and put all country names init. Then you had to change the country submission form on register.asp.Plus, plus, plus,..,..<br><br>I doubt that it's worth the time since unlike dj air I do not see it asa security hole. The country gets checked for invalid tags and SQLinjection, so there won't be a problem with it. Warn the user and if hedoes it again, ban him. <br><br>As a user, you need to have some knowledge to manipulate the formsubmission, so that problem will not occur very often, if it does everhappen again at all.<br>]]>
   </description>
   <pubDate>Mon, 06 Jun 2005 16:47:22 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84710.html#84710</guid>
  </item> 
  <item>
   <title><![CDATA[Locati&#111;n :    sfd19 wrote:By manipulating...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84690.html#84690</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=20721">deathchaoz</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 06&nbsp;June&nbsp;2005 at 10:15am<br /><br /><table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by sfd19" alt="Originally posted by sfd19" style="vertical-align: text-bottom;" /> <strong>sfd19 wrote:</strong><br /><br />By manipulating the form submission on register.asp<br><br>To prevent it you must add a check that the submitted country matches one of your list.<br><br>Also, you should seriously warn that user.<br></td></tr></table><br><br>Happen to be able to tell me how?<br>]]>
   </description>
   <pubDate>Mon, 06 Jun 2005 10:15:45 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84690.html#84690</guid>
  </item> 
  <item>
   <title><![CDATA[Locati&#111;n : this can be seen as a security...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84678.html#84678</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2216">dj air</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 06&nbsp;June&nbsp;2005 at 8:19am<br /><br />this can be seen as a security hole.<br><br>i'll let boRg know about this<br>]]>
   </description>
   <pubDate>Mon, 06 Jun 2005 08:19:45 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84678.html#84678</guid>
  </item> 
  <item>
   <title><![CDATA[Locati&#111;n : By manipulating the form submission...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84676.html#84676</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18731">sfd19</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 06&nbsp;June&nbsp;2005 at 7:35am<br /><br />By manipulating the form submission on register.asp<br><br>To prevent it you must add a check that the submitted country matches one of your list.<br><br>Also, you should seriously warn that user.<br>]]>
   </description>
   <pubDate>Mon, 06 Jun 2005 07:35:20 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84676.html#84676</guid>
  </item> 
  <item>
   <title><![CDATA[Locati&#111;n : Someone changed their location...]]></title>
   <link>https://forums.webwiz.net/location_topic15373_post84666.html#84666</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=20721">deathchaoz</a><br /><strong>Subject:</strong> 15373<br /><strong>Posted:</strong> 06&nbsp;June&nbsp;2005 at 12:13am<br /><br />Someone changed their location to their name on the web wiz forum I use, How could they have done it?]]>
   </description>
   <pubDate>Mon, 06 Jun 2005 00:13:33 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/location_topic15373_post84666.html#84666</guid>
  </item> 
 </channel>
</rss>