Author Topic: Calling a Web Master..  (Read 1841 times)

0 Members and 1 Guest are viewing this topic.

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Calling a Web Master..
« on: February 23, 2012, 06:35:47 AM »
Just curious, was using IE9, highlighted a word to do a search. The search attempt (Google) resulted in a message; "Internet Explorer has modified this page to help prevent cross-site scripting." The delivered page merely had a "#" in the upper-left.

What exactly is cross-site scripting and how is it done? I'm assuming is it not a good thing from a user perspective. Is it simply some sort of redirection?
We'll all be someone else's PO some day.

Offline CycleRanger

  • No comment about being an
  • Really Old Timer ...
  • *******
  • Posts: 5,710
  • Central Texas Shop Manual Advocate
Re: Calling a Web Master..
« Reply #1 on: February 23, 2012, 06:47:33 AM »
Yes, it's reacting to the fact that using the google search sends you to google.
For example: (http://www.google.com/cse?cx=partner-pub-9323359806520211%3A1305160748&ie=UTF-8&q=engine+stand&sa=Search&siteurl=forums.sohc4.net%2Findex.php%3Faction%3Dunread&ref=#gsc.tab=0&gsc.q=engine%20stand&gsc.page=1)

It's a defensive setting to prevent possible hax.
Do you have a copy of the Honda Shop Manual or Parts List for your bike? Get one here:
https://www.honda4fun.com/materiale/documentazione-tecnica
CB750K5        '79 XL250s     CL350K3
CB750K3        '76 XS650      '76 CJ360T

Offline FuZZie

  • Expert
  • ****
  • Posts: 1,222
  • If I is expert, I can has cheezburger?
Re: Calling a Web Master..
« Reply #2 on: February 23, 2012, 08:36:44 AM »
Just curious, was using IE9, highlighted a word to do a search. The search attempt (Google) resulted in a message; "Internet Explorer has modified this page to help prevent cross-site scripting." The delivered page merely had a "#" in the upper-left.

What exactly is cross-site scripting and how is it done? I'm assuming is it not a good thing from a user perspective. Is it simply some sort of redirection?

It's a little more involved than a hax, It's usually a more to do with social engineering. Best way to understand is example chain of events.

First well use 1bank as where your heading for and this is the url:
Code: [Select]
www.1bank.com
so whoever has managed to get some control on that site just one little line that redirects you to his site:
Code: [Select]
www.Ibank.com

Your redirected to a copy of 1bank it looks good so you enter your user name and password then you'll get some popup or page saying you need to verify with your security answers so you type in your mothers maiden name or your son's date of birth .... and the page fails, you get a error and are told to return later.

What happened is you just gave a thief all your info and he knows the site already very soon your going to take a hit at 1bank sorry.

So a more historic example would be this url:
Code: [Select]
www.paypaI.com or
Code: [Select]
www.paypa!.comCan you see the problem with it bob?
« Last Edit: February 23, 2012, 08:58:20 AM by FuZZie »

Offline BobbyR

  • Really Old Timer ...
  • *******
  • Posts: 12,365
  • Proud Owner of the Babe Thread & Dirty Old Man
Re: Calling a Web Master..
« Reply #3 on: February 23, 2012, 08:54:32 AM »
You have an exclamation mark where the L should be. At a quick glance it looks fine. great example!
Dedicated to Sgt. Howard Bruckner 1950 - 1969. KIA LONG KHANH.

But we were boys, and boys will be boys, and so they will. To us, everything was dangerous, but what of that? Had we not been made to live forever?

Offline FuZZie

  • Expert
  • ****
  • Posts: 1,222
  • If I is expert, I can has cheezburger?
Re: Calling a Web Master..
« Reply #4 on: February 23, 2012, 09:01:58 AM »
Would have been better bobby  if I had controlled the fonts ;)
« Last Edit: February 23, 2012, 09:28:10 AM by FuZZie »

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Re: Calling a Web Master..
« Reply #5 on: February 23, 2012, 09:26:30 AM »
Thanks all for th info, my curiosity is now satisfied.  ;)
We'll all be someone else's PO some day.

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Re: Calling a Web Master..
« Reply #6 on: February 23, 2012, 01:54:11 PM »
Odd little follow-up on this. My original search was a book title enclosed in single quotes. This produced the message in question. On another site, another book title only in single quotes, produced the same results. If I search the same thing(s) independently with single quotes (i.e., in the search bar) I also get the message. However, if I search the same titles with double quotes as it the usual way to indicate a book title, I get valid results. What might the significance of the single quotes be in this regard?
We'll all be someone else's PO some day.

Offline FuZZie

  • Expert
  • ****
  • Posts: 1,222
  • If I is expert, I can has cheezburger?
Re: Calling a Web Master..
« Reply #7 on: February 23, 2012, 05:26:37 PM »
I don't search books much but, it should depend on the search engines or browsers security rule set.

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Re: Calling a Web Master..
« Reply #8 on: February 23, 2012, 06:10:16 PM »
It does it on any single word or string. It's almost as though it is being interpreted as a programming literal. ??
We'll all be someone else's PO some day.

Offline FuZZie

  • Expert
  • ****
  • Posts: 1,222
  • If I is expert, I can has cheezburger?
Re: Calling a Web Master..
« Reply #9 on: February 23, 2012, 07:58:32 PM »
What are you searching with?

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Re: Calling a Web Master..
« Reply #10 on: February 24, 2012, 03:14:32 AM »
What are you searching with?

Win 7, Google search engine and IE9.
We'll all be someone else's PO some day.

Offline FuZZie

  • Expert
  • ****
  • Posts: 1,222
  • If I is expert, I can has cheezburger?
Re: Calling a Web Master..
« Reply #11 on: February 24, 2012, 07:24:27 AM »
I can't help much with IE as I run on Linux, I only emulate IE. Witch I do to make sure pages will display correctly in it. I do this because Microsoft has a history of ignoring the web standards (last few versions they have been improving though). I did a quick check in Google search and didn't see your issue though.

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Re: Calling a Web Master..
« Reply #12 on: February 24, 2012, 07:38:05 AM »
Thanks. Not a big deal, I was just curious.
We'll all be someone else's PO some day.

Offline BobbyR

  • Really Old Timer ...
  • *******
  • Posts: 12,365
  • Proud Owner of the Babe Thread & Dirty Old Man
Re: Calling a Web Master..
« Reply #13 on: February 24, 2012, 09:02:54 AM »
Google has a probelm searching for a phrase. They added a feature on the side under search tools that allows you to specify exact words in exact order.
Dedicated to Sgt. Howard Bruckner 1950 - 1969. KIA LONG KHANH.

But we were boys, and boys will be boys, and so they will. To us, everything was dangerous, but what of that? Had we not been made to live forever?