Sr. Web Developer
mediabistro.com
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume

Comments for: sporty20001102

Message # 1018799:
Date: 02/07/04 20:29
By: john smith
Subject: RE: Credit card hack -- will that work??

Regarding the credit card hack described in this article....I just don't see how that would work?

If someone were to put in the bogus HTML into the CC field, as described above and pressed the submit button, it would re-display the page with the extra field. Then if that same person were to put a credit card number into the second feild and submitted the form again, it would send the credit card to the other website. Basically, the hacker would be sending his own credit card to some other site.

However, all other people that were using the form would have the form displayed correctly went they went to the page. They would then use the form as intended. The input the hacker submitted would only affect the instance of the program that he was running.

If I am wrong about this, perhaps someone could explain it to me since this example only seems like it would be a problem if the hacker could affect the actual php code stored on the server with his bogus form input

Previous Message | Next Message


Comments:
Do you wanna buy Credit Card ?Migawa12/29/04 01:54
how do i hack credit cardstosin11/18/04 13:43
RE: Credit card hack -- will that work??john smith02/07/04 20:29
A generic validation script for web forms?Kelvin Poon09/19/03 11:22
RE: Where to check?Jester04/05/03 12:03
Where to check?Ian10/09/02 02:11
Real Time DataJohn10/06/02 10:27
RE: What about this ?Chris09/23/02 17:02
What about this ?Staffan Söderström09/13/02 06:37
RE: Credit card hack -- will that work??Andy Christianson09/06/02 01:50
RE: Credit card hack -- will that work??Andy Christianson09/03/02 16:51
RE: Javascript form validation workaroundMark Bembnowski08/20/02 11:54
Security of $_POST[]Jeremy Brown07/28/02 15:55
RE: Very dangerous sql code possibleDaniel Tsadok07/16/02 06:24
Javascript form validation workaroundDaniel Tsadok07/16/02 05:56
Somebody has hacked my credit cardParul Asha Singh07/14/02 11:11
RE: When is it too muchHari Usmayadi07/07/02 22:29
check inputWolfgang Hamann04/14/02 03:28
unknown extensionPeter van Rooijen04/03/02 02:13
excellent !!mika02/02/02 09:15
Un Normalised Table Into Un Normalised DataMehmood Ahmed Chadhar09/26/01 03:00
RE: Credit card hack -- will that work??Grasso08/06/01 00:23
RE: ...basic problem..Frans-Jan Wind07/24/01 02:38
Page CachingUnknown07/19/01 02:16
...basic problem..Van Tri05/04/01 08:49
RE: Very dangerous sql code possibleChris Boget04/04/01 13:16
good solutionigor03/22/01 13:24
RE: Credit card hack -- will that work??Michael McGinley03/13/01 11:44
RE: http_reffererJosh03/11/01 02:19
Credit card hack -- will that work??Chuck Clayton02/15/01 11:13
RE: Very dangerous sql code possibleWojtek12/24/00 07:18
RE: http_reffererMichael Rowe11/26/00 00:46
Very dangerous sql code possibleGreg MacLellan11/22/00 12:18
Checking for bad SQLMartijn11/14/00 11:05
http_reffererAdam Zochowski11/13/00 12:51
It's array_push not push_arrayJohn Miller11/10/00 15:34
RE: Also need to strip HTML tags from inputspencer p11/10/00 11:53
Also need to strip HTML tags from inputJohn Lim11/09/00 10:03
RE: When is it too muchspencer p11/04/00 16:59
RE: When is it too muchTim Frank11/03/00 23:38
When is it too muchCCBCREG11/03/00 13:35
ArticleMarc11/03/00 03:14
Excellent !Bjorn Sodergren11/03/00 01:23
 

If you are looking for help, please post on the appropriate forum here. Your questions will be answered much more quickly.

Add A Comment:

Name:

Email:

Subject:

Message:

To reduce spam posts, messages are now manually approved

You are not [logged in]. That means your account will not get credit for this post.