eQSL.cc Forum
Help!  eQSL.cc Home  Forums Home  Search  Login 
Viewing User Profile for: KC2CIW Michael W Coles
About Contact
Joined: Jul 5, 2007 05:56 PM
Last Post: Jul 6, 2007 04:03 PM
Last Visit: Jul 12, 2007 03:00 PM
Website:  
Location:
Interests:
Email: bluelip@gmail.com


Send Private Message
Post Statistics
KC2CIW Michael W Coles has contributed to 1 posts out of 11719 total posts (0.01%) in 6,296 days (0.00 posts per day).

20 Most recent posts:
Getting more eQSLs » Can you download rec'd QSL to log? Jul 6, 2007 04:03 PM (Total replies: 5)

Be careful of the data that is passed through to eQSL. It doesn't handle exceptions well. (apps/database barfs when given unexpected data)

EDIT: I should clarify. This website has some issues w/ input validation.

Before I started to move my logs into the system, I wanted to see how 'hacker resistant' the site is/was. Without providing a step-by-step procedure for others to follow, all I shall say is that modifying the GET/POST variables of forms causes the system to generate a fault.


I do wish the site the best. I would like to see security taken more seriously and possibly even have a digital signing of the eQSL available. Maybe that would give ARRL a warm-and-fuzzy feeling about the security/accuracy of the data here.

Best wishes to everyone,
mike





KC2CIW Michael W Coles
Edited by KC2CIW Michael W Coles on Jul 6, 2007 at 04:23 PM
Edited by KC2CIW Michael W Coles on Jul 6, 2007 at 04:24 PM