Guestbook  
Write a comment for this guestbook entry. Back to Guestbook | Administration
Sign the Guestbook:
18167) IP logged  Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/523.12.2 (KHTML, like Gecko) Version/3.0.4 Safari/523.12.2  View Web Page 
Jason Yerardi  
Location:
-
Saturday, 2. February 2008 20:29  Write a comment

I have been using your Guestbook for half a year now and really like it. However, I believe there a couple things you could do to improve security.

The following has happened to me several times, using version 2.4.3: Someone creates a post with a "refresh" or "script" html tag, which automatically redirects to a hacker's web site. This happens even if html and ag codes are turned off.

For some of these, I've been able to hit "Cancel" while loading the page (to keep it from reaching the suspect entry), go into EasyAdmin, and remove. However the latest script that hacked my Guestbook was more severe. I had to actually go into the database and remove the entry from the table. Good thing I know SQL!

Anyway, great product...would just be nice to see an update that prevents "refresh" and "script" statements in the comment field.
Comments:
Name:
Password: