<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Parameter-Pollution on pok3 // security notes</title><link>https://pok3.xyz/tags/parameter-pollution/</link><description>Recent content in Parameter-Pollution on pok3 // security notes</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 27 Mar 2024 18:59:35 +0100</lastBuildDate><atom:link href="https://pok3.xyz/tags/parameter-pollution/index.xml" rel="self" type="application/rss+xml"/><item><title>Perfect Shop</title><link>https://pok3.xyz/posts/openecsc2024/perfect-shop/</link><pubDate>Wed, 27 Mar 2024 18:59:35 +0100</pubDate><guid>https://pok3.xyz/posts/openecsc2024/perfect-shop/</guid><description>&lt;h2 id="initial-thoughts" class="heading"&gt;&#10; &lt;a href="#initial-thoughts" class="heading-anchor" aria-label="Link to this section"&gt;#&lt;/a&gt;Initial thoughts&#10;&lt;/h2&gt;&#10;&#10;&lt;h3 id="first-look-at-the-webpage" class="heading"&gt;&#10; &lt;a href="#first-look-at-the-webpage" class="heading-anchor" aria-label="Link to this section"&gt;#&lt;/a&gt;First look at the webpage&#10;&lt;/h3&gt;&#10;&lt;p&gt;In my initial exploration of the website, I noticed it had various products listed with brief descriptions and prices.&lt;/p&gt;&#10;&lt;p&gt;&#10;&#10;&lt;figure class="md-image"&gt;&#10; &lt;a href="https://pok3.xyz/posts/openecsc2024/perfect-shop/img/perfectshop_startpage.png" target="_blank" rel="noopener" data-zoom&gt;&#10; &lt;picture&gt;&#10; &lt;source srcset="https://pok3.xyz/posts/openecsc2024/perfect-shop/img/perfectshop_startpage_hu_6c730f9302849c79.webp" type="image/webp"&gt;&#10; &lt;img src="https://pok3.xyz/posts/openecsc2024/perfect-shop/img/perfectshop_startpage.png" alt="Perfectshop Startpage" width="1887" height="831" loading="lazy" decoding="async"&gt;&#10; &lt;/picture&gt;&#10; &lt;/a&gt;&#10;&lt;/figure&gt;&#10;&lt;/p&gt;&#10;&lt;p&gt;Seeing a search bar raised some suspicion for me because they&amp;rsquo;re often used for sneaky attacks like reflected &#10;&lt;a href="https://en.wikipedia.org/wiki/Cross-site_scripting" class="ext" target="_blank" rel="noopener noreferrer"&gt;Cross-site scripting (XSS)&lt;/a&gt;&#10; or &#10;&lt;a href="https://en.wikipedia.org/wiki/SQL_injection" class="ext" target="_blank" rel="noopener noreferrer"&gt;SQL injections&lt;/a&gt;&#10;. Additionally, I stumbled upon an admin page where we could tweak product details, although it seemed pointless without an admin password.&lt;/p&gt;</description></item></channel></rss>