View Single Post
  #9   Spotlight this post!  
Unread 29-06-2009, 16:41
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

Quote:
Originally Posted by OScubed View Post
Have you commented out the following JS to be sure they're not injecting the div:

Colourloverscolorpicker.js
print.js
ddaccordion.js
lnews.js
lnews.js and print.js are scripts we've written, and both of the other scripts have been heavily modified, and do not reference any other files, unless i missed something... (after all, i was working late at night)

now that you mention it,i've re-checked the scripts, and they are all clean...

the only scipt i haven't modified is http://ajax.googleapis.com/ajax/libs.../jquery.min.js, but i use that on several other sites without any issues...

looking at the pages referenced in the ghost div, it doesn't seem to be for advertizing... all the pages seem to be located on sites they have no relation to, most of which are schools and universities, and all of which run moodle

i wasn't able to get to the moodle discussuion board, as i do not have an account... however, i will talk with the tech coordinator at school to see if he has one.

thanks for the thought though,

-Z
__________________
[center]