Slide 13
Slide 13 text
Practice: Fix Ivan The Terrible's Blog
• Start with the "insecure" branch
• Use the SQL / search query below to test SQL Injection
• Play with XSS by inserting JavaScript into the post and see what chaos you
can make!
foo%'); INSERT INTO posts
(id,title,body,created_at,updated_at) VALUES
(99,'hacked','hacked
alright','2013-07-18','2013-07-18'); SELECT
"posts".* FROM "posts" WHERE (title like
'%anything
Friday, July 19, 13