XvExodusvX wrote:
Thanks, now you've given spyware something to work on.
Nah, if they are true haxxorz they would already know that and would work out that the location field has 41 spaces, which allows nicely for a 3.3 domain name and a 1.2 filename.. or... they would just assume that the database field is likely 50 or 255 characters, copy the HTML from the user profile management to their own server, remove the field restriction limit and save whatever string they want up to 255 chars, whatever does not return a mySQL error.
So.. the very knowledgeable all knowing admins I am sure have blocked posting to their cgi's from other sites, have limited the actual field size in the mySQL table field. So the odds of client code being buggered with are only 30%.. Right?
Note: All such activity would be very traceable and the admins could shut it down very fast by nuking the account in question. So I honestly don't think they are worried. Edit:
for Jophiel
Edited, Fri Jan 21 14:02:36 2005 by ElderonXI