Solved

JavaScript send data to hidden fields on remote server

Posted on 2014-11-04
3
187 Views
Last Modified: 2014-12-10
Hi,

We have an FTP site with PHP that requires a username and password.  This site is for a school to upload videos to.  They are do not want have the students log in and would like the username and password passed for them through the CMS

The CMS allows for JavaScript to be implemented on their custom pages

For security purposes, I do not want to disable the username an password option.  I tried XSS but that is not working.  I tried:

https;//myftsite.com/index.php?username=test

 I need to find a way for those values to be passed through their CMS using JavaScript or HTML (their CMS will only support these).  Currently they are just using iframes and the url to connect to the site

Thank you for your help in advance
0
Comment
Question by:thomasm1948
  • 2
3 Comments
 
LVL 83

Accepted Solution

by:
Dave Baldwin earned 500 total points
ID: 40422237
If you put the username and password in hidden fields on an HTML page, I can pretty well guarantee you that the students will have them in a week.  Many people 'View Source' on web pages and data in 'hidden fields' are there in plain text.

Look into using a PHP page to do the uploading although the size of the videos may make that impossible.
0
 

Author Comment

by:thomasm1948
ID: 40422342
These are small videos less that 2GB.  I was hoping that JavaScript could pass the values.  We are not worried about the student knowing the passwords being that this just going to be for a competition that they are having.  The instructor just doesn't want them to be hindered by a username and password.

So far the user security for is that once it is uploaded, even if they chose to use FileZilla, they will not be able to view any of the files on the server.  They student login can only upload files and the Instructor username has full permissions
0
 

Author Comment

by:thomasm1948
ID: 40422347
We are using PHP for the upload page.  Currently it requires a username and password.

The FTP site is at a remote location and has a PHP login page for uploading the files.

The CMS that the school is using makes it hard.  I tried C# inline coding and that does work on their system
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CSS style formatting? 2 31
HTML5 storage and web apps 11 44
Find unused columns in a table 12 68
PHP Command to Open New Tab/Page using Window.Open 3 4
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
A quick Powershell script I wrote to find old program installations and check versions of a specific file across the network.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…
The viewer will the learn the benefit of plain text editors and code an HTML5 based template for use in further tutorials.

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question