Login Register




Poll: Your favourite vulnerabillity?
You do not have permission to vote in this poll.
SQLi?
45.45%
5 45.45%
XSS?
45.45%
5 45.45%
A third vulnerabillity?
9.09%
1 9.09%
Total 11 vote(s) 100%
* You voted for this item. [Show Results]



XSS vs SQLi filter_list
Author
Message
RE: XSS vs SQLi #9
I like more XSS because its more transparent. With SQLi if you make a mistake, you don't have to get exact reason why it doesn't work. The actual syntax runs on the server therefore for you, as a client, most of the process is invisible.

While for XSS, the injection runs on your computer (the client) and you see exactly what goes on. You can have a pretty precise guess what is happening on the server side when reading the output of some page. Also XSS isn't considered as high risk as SQLi (I say the risk levels are same! but whatever...) so you don't really need to cover yourself so much. And if you report it, you don't look so suspicious. (Honestly, would you be more suspicious of a guy reporting you how he hacked into your database or about a guy showing you how to pop-up an alert box?)
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply





Messages In This Thread
XSS vs SQLi - by Asuna_mybb_import7736 - 09-25-2012, 09:57 PM