I just talked to Gareth about his latest vector submission and got the
idea of building up a wiki to persist the issues found on slackers and
the group like:
- interesting but hard to understand vectors
- strange JavaScript behavior
- more strange JavaScript behavior
- parsing peculiarities for browsers and their components
- etc.
What do you think? Currently we have the problem that the information
is there but too wide spread and not very usable - a wiki should help
fighting those hitches and with the information already gathered we
could build up a pretty unique knowledge base.
Greetings,
.mario
On Sep 30, 3:59 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:
http://wiki.splitbrain.org/wiki:dokuwiki
Looks promising too I think...
On 1 Okt., 09:23, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:
> We could use the existing Trac Wiki or I could set up a new. What domain
> would you propose to use for this purpose? We could use wiki.php-ids.org or
> something with the h4k.in domain or even register a new one.
>
> I'd propose the easiest way and use wiki.php-ids.org combined with the trac
> wiki which is pretty comfortable for posting code and other elements.
>
> 2007/10/1, thornmaker <thornma...@gmail.com>:
Actually I had thought about this some days ago, and collected few
vectors.
Here is how an entry in the list looked like..
Decoded Version:
{z=(1==4)?here:{z:(1!=5)?'':be}}
{y=(9==2)?dragons:{y:'l'+z.z}}
{x=(6==5)?3:{x:'a'+y.y}}
{w=(5==8)?9:{w:'ev'+x.x}}
{v=(7==9)?3:{v:'tr(2)'+z.z}}
{u=(3==8)?4:{u:'sh.subs'+v.v}}
{t=(6==2)?6:{t:y.y+'ocation.ha'+u.u}}
{s=(4==3)?3:{s:(8!=3)?(2)[w.w]:z}}
{r=s.s(t.t)}
{s.s(r)+z.z}
On the first line is the name of the inventor, next is the url/post
body used (I think this is important as it indicates how certain chars
may need to be url encoded),
next section is the broken down vector.
It would be nice to have an explanation in english along with every
vector. But I am not sure about the feasibility because we have too
many vectors.
we could collect all the entries now and then add explanation
gradually.
What do you guys think?
Regards,
Kishor
On Oct 1, 3:56 am, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:
On Oct 1, 2:13 pm, kishord <kishor.t...@gmail.com> wrote:
> Thats a great idea!
>
> Actually I had thought about this some days ago, and collected few
> vectors.
>
> Here is how an entry in the list looked like..
>
> 1 Thornmaker
> *************************************************************
> URL/POST:http://demo.php-ids.org/?test=%7B%7A%3D%28%31%3D%3D%34%29%3F%68%65%72...
Greetz!!
On 1 Okt., 09:56, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote: