chizu
01-31-2008, 01:18 AM
Hello. I recently got hacked because of my carelessness. The person used Ajax and javascript to get my password and username variables and then logged into people's accounts. They typed this code into their profile and then when people viewed it, the information was sent to them through 'Starmail', the personal messaging system on my website.
I was wondering if there is anyway to protect against this kind of thing. I would like to still allow HTML, CSS, and javascripts that don't kill my site in user profiles, but how should I go about preventing other things like Ajax and other php codes? Thanks!
I was wondering if there is anyway to protect against this kind of thing. I would like to still allow HTML, CSS, and javascripts that don't kill my site in user profiles, but how should I go about preventing other things like Ajax and other php codes? Thanks!