Bookmark and Share

Wednesday, April 22, 2009

HOWTO NOT develop a web login page

Yesterday I was mining some information about bar codes on google, and I found this page:

After some surfing I found a login page:
zrclip_002n5df8c113.png
Damnn... I neeed a  password!
Here is the viewsource of the page:

Interesting, the Archivio checks with an ajax service...
Here is the code of the Archivio function:

Uhmmm... flag? Let me find on the upper code....

Ok, now we try one of these flags...:

Bingo! Here is the magical access to the page.

Don't hide the key of your house near the house door..