开发者

Can someone explain last year's reddit exploit to me?

开发者 https://www.devze.com 2022-12-22 05:21 出处:网络
Last year a user managed to inject arbitrary javas开发者_如何学编程cript into reddit\'s markdown syntax. Can someone explain how this was done and how I can test whether my site is similarly vulnerabl

Last year a user managed to inject arbitrary javas开发者_如何学编程cript into reddit's markdown syntax. Can someone explain how this was done and how I can test whether my site is similarly vulnerable?


Blog entry on the exploit:

http://blog.reddit.com/2009/09/we-had-some-bugs-and-it-hurt-us.html

The patch that fixed it:

https://github.com/reddit/reddit/commit/1f1f0606f5b6bf14a0db55a28cfd03e1e42e3550

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号