[Solved]: Disallowed html tags and SQL Querys [forum issue]

Announcements and for questions/problems..
Post Reply
User avatar
t3hmadhatt3r
forum buddy
forum buddy
Posts: 16
Joined: 11 May 2009, 16:00
14

[Solved]: Disallowed html tags and SQL Querys [forum issue]

Post by t3hmadhatt3r »

I've been trying to post some tutorials on XSS and one on Oracle SQL injection but I'm having many problems. When I try to post anything with a few html tags in it even if its inside

Code: Select all

 and/or [quote] it will only give me the error message "The html tags you used are disabled". When I try to post the oracle sql injection tutorial, and this is really weird, I get sent back to the home page. Why is that? I think its because of some blacklist you guys are using but, SQL Query's should be allowed inside [quote] and or [code]  tags... Is there anything that can be done to fix this issue?

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

This is an old issue that we have had for like forever ^^ Fixing it now would take too much time from other more important projects and might risk that sites security in the process. We are working on setting up a new cms, so no use spending too much time fixing this one ;)
"The best place to hide a tree, is in a forest"

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

:D
yea we block that stuff, strict rulesets. so we have a code.suck-o.net url that we dump script on.

http://code.suck-o.com/" onclick="window.open(this.href);return false;

link your tut to reference where it is on the pastebin
ie ..code.suck-o.com/101



DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
t3hmadhatt3r
forum buddy
forum buddy
Posts: 16
Joined: 11 May 2009, 16:00
14

Post by t3hmadhatt3r »

Oh. Great! Thanks.....

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

Suck-o Help Desk Ticket # 13370
[DNR crumbles up the ticket and makes a three-point shot into the round filing cabinet]

Solved. :wink:

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
CommonStray
Forum Assassin
Forum Assassin
Posts: 1215
Joined: 20 Aug 2005, 16:00
18

Post by CommonStray »

Code: Select all

circuitbomb pops head out of the round filing cabinet and fires a spitwad at DNR

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

Code: Select all

Big-E jumps in on role playing dressed as Tiberius the great Roman General! 


....

Code: Select all

...runs! 

Post Reply