|
|||||||||||
|
RE: View and edit hidden HTML form fields (fwd)
From: Jordi Molina <warper(at)eresmas.com>
Date: Thu Jun 12 2003 - 13:15:30 EDT
I think that the application is good for checking out if it is any hidden field in the form that stores sensible information. I have to say, too, that, in many ways, this kind of "programming error" has been checked by anyone that works with dynamic web application. Ç Anyone knows where these variables are stored on client side? It's there any program like this one that allows to check the content of session variables instead of hidden fields in html forms? Thanks in advance
PS: Excuse me for my bad English, I think I have to practice a little
more :)
Indeed. I certainly wasn't claiming any greatness on the part of the program, especially since we're not a Window's shop -- it doesn't particularly apply to me. My point was that while I may be comfortable with using Perl/LWP and regular expressions as a coder, these are things I use on a regular basis while doing assessments. However, for others (such as many who I work with that do not code) this provides a simple way to demonstrate various simple client-side state weaknesses. I would also agree that there are many other tools out there that do similar things (and much more.) Especially where actual assessments are the goal. I was just simply stating that for its intended purpose, it works, and integrates into IE as a side bar making it easy to tote around. (Again, For those who use IE... )
On Wed, 2003-06-11 at 17:01, Tim Greer wrote:
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:52 EDT |
||||||||||
|
|||||||||||