manipulating query strings

From: Vel (vel_at_sympatico.ca)
Date: 02/23/04

  • Next message: Javier Fernandez-Sanguino: "Re: nessus which plug'in reports which vulnerability?"
    To: <pen-test@securityfocus.com>
    Date: Mon, 23 Feb 2004 11:43:27 -0800
    
    

    Hello Group,

    Is there a way to send values to hidden fields ,

    i.e Input tags with type=hidden attribute a value from the URL if the action
    attribute on the FORM is ACTION ?

    e.g:

    <FORM form1 ACTION= '/search/search.asp' METHOD=post>

    <Input type=hidden name=serverName value=www.abc.com>
    <Input type=hidden name=serverName value=www.def.com>

    ---------------------------------------------------------------------------

    Given the Method is "POST", can I pass values to the Hidden Input fields
    using the URL. i.e URL manipulation ?
    I know I can pass variables in URL to Server side script variables if METHOD
    is "GET".

    But how about POST method ?

    Thanks.

    Kumar.

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_pen-test_040219
    ----------------------------------------------------------------------------


  • Next message: Javier Fernandez-Sanguino: "Re: nessus which plug'in reports which vulnerability?"

    Relevant Pages

    • RE: manipulating query strings
      ... I know I can pass variables in URL to Server side script variables if METHOD ... But how about POST method? ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
      (Pen-Test)
    • values are stored in hidden fields
      ... Once the security mode is checked I assume the protocol is ... the hidden fields are not being populated. ... >It appears to be a bug is in Internet Explorer caused by ... Once there select "Advanced" go to the HTTP section ...
      (microsoft.public.security)
    • Re: How to pass an ID in hidden variable.
      ... I'd try to avoid that if at all possible, spoofing hidden fields is a known ... hack and I was at DevDays ASP.NET Security discussion and they were ... I think Session State ... should get you what you need and session variables are really easy to use. ...
      (microsoft.public.dotnet.framework.aspnet)