RE: manipulating query strings

From: Kris Wilkinson (kris_at_Titan-Networks.ca)
Date: 02/24/04

  • Next message: Mike Hoskins: "Re: question regarding nessus plug-in 10595 DNS AXFR"
    Date: Tue, 24 Feb 2004 11:16:40 -0700
    To: "Vel" <vel@sympatico.ca>, <pen-test@securityfocus.com>
    
    

    You shouldn't have to worry about this if you are always defining the
    variable "serverName" each time the script loads.

    For example ...

    If you have

    <Include> config file here w/ variable serverName || just a simple
    serverName = 'whatever'
    <connect> to server w/ variable serverName

    the serverName variable would overwrite any incoming post information
    when it fetches the config file.

    -----Original Message-----
    From: Vel [mailto:vel@sympatico.ca]
    Sent: Monday, February 23, 2004 12:43 PM
    To: pen-test@securityfocus.com
    Subject: manipulating query strings

    Hello Group,

    Is there a way to send values to hidden fields ,

    i.e Input tags with type=hidden attribute a value from the URL if the
    action
    attribute on the FORM is ACTION ?

    e.g:

    <FORM form1 ACTION= '/search/search.asp' METHOD=post>

    <Input type=hidden name=serverName value=www.abc.com>
    <Input type=hidden name=serverName value=www.def.com>

    ------------------------------------------------------------------------

    ---
    Given the Method is "POST", can I pass values to the Hidden Input fields
    using the URL. i.e URL manipulation ?
    I know I can pass variables in URL to Server side script variables if
    METHOD
    is "GET".
    But how about POST method ?
    Thanks.
    Kumar.
    ------------------------------------------------------------------------
    ---
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.
    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.
    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_pen-test_040219
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Mike Hoskins: "Re: question regarding nessus plug-in 10595 DNS AXFR"

    Relevant Pages

    • Re: Windows 2000 Login problems
      ... > | Event Type: Success Audit ... > | Event Source: Security ... > | Computer: SERVERNAME ... > | User Name: PhilTest ...
      (microsoft.public.win2000.advanced_server)
    • Event IDs 565, 675, 537
      ... Event Type: Failure Audit ... Event Source: Security ... Event Category: Account Logon ... Computer: SERVERNAME ...
      (microsoft.public.win2000.security)
    • Re: 404 error for certain extension on IIS 6
      ... > IIS 6.0 does not serve unknown extensions by default. ... > security feature. ... > otherwise, click the HTTP Headers tab, and then click the Mime Types ... > servername), ...
      (microsoft.public.inetserver.iis)
    • Re: Page cannot be displayed error no. 500
      ... I would look at their IE Security settings. ... when changing the url from the <servername> to the IP address, ... No configuration changes has made. ...
      (microsoft.public.sharepoint.windowsservices)