Thread Rating:
  • 2 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5

[MyBB Plugin] Board Announcements Manager (For 1.6 and 1.8)

#19
I just finished a full on round of as much penetration testing as possible. Tried throwing script, onchanges, onclicks, rogue characters, whatever I could think of. Did it in the class fields, in the ACP, in the announcement, in the usergroup fields, and anywhere else that I could possibly think of. Things that take numeric values even, things that aren't even the announcement.

It even sanitizes the username if a user's username is javascript. MyBB doesn't even allow this, but if they found a way to change their username to javascript characters and tried to run it past the {username} tag, BAM won't even let this one past.

It passed with flying colors. This thing has full support for HTML for everything except javascript and rogue stuff. Finna

Reply


Messages In This Thread
RE: [MyBB Plugin] Board Announcements Manager (For 1.6 and 1.8) - by Guest - February 7th, 2015 at 8:20 PM
RE: [MyBB Plugin] Board Announcements Manager (For 1.6 and 1.8) - by Darth-Apple - February 15th, 2020 at 1:21 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  why or by which plugin Mybb hacked? tc4me 8 3,795 February 19th, 2021 at 5:08 AM
Last Post: tc4me
  [MyBB Plugin] Average Profile Ratings Darth-Apple 8 5,367 October 22nd, 2020 at 6:41 AM
Last Post: tc4me
  Simple Reputation Bars [MyBB Plugin] Darth-Apple 7 4,311 October 22nd, 2020 at 4:25 AM
Last Post: tc4me
  MyBB Post Activity Plugin Guardian 8 5,533 May 3rd, 2020 at 7:36 PM
Last Post: tc4me



Users browsing this thread: 2 Guest(s)

Dark/Light Theme Selector

Contact Us | Makestation | Return to Top | Lite (Archive) Mode | RSS Syndication 
Proudly powered by MyBB 1.8, © 2002-2024
Forum design by Makestation Team © 2013-2024