The bucket that holds water is made up of many wooden boards, and the amount of water is determined by these boards. If one of the wooden boards is short, the amount of water in the barrel is limited by the short board. This short board has become a "limiting factor" (or "short board effect") for this bucket to hold water "). To increase the volume of water in this bucket, you can only change the short board or extend the short board. People sum up this rule as "Barrel Principle" or "barrel Law", also known as "short board theory ". -- From Baidu Jun detailed description: site: http://yujian.renren.com, although the station for user input filtering, but still can bypass. Multiple storage sites can cause account hijacking. Proof of vulnerability: 1. Cross-Site restriction can be bypassed in terms of name, information, and hobbies, here we have made some restrictions. The filter filters keywords such as script/onerror and has a limit of 200 characters! Therefore, IE chrome the cookie intercepted by this blacklist filter is bypassed: The popularity is still high ...... Therefore, the yujian.renren.com domain smoothly enters the renren.com domain, so far the main site is down. Hijack two sister accounts:
New Year and then send a URL jump: http://www.renren.com/pages/autoLogin-ads.jsp? MainPage = http://wooyun.org do you mean too-0-
Solution:
The whitelist may be better.