Re: this is tough!

Christoph Wernli (cw@dwc.ch)
Mon, 02 Apr 2001 17:48:27 +0200


--------------msEFD595E913BCDE6ED6B25641
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Alan Jiang wrote:
> 
> I have a tough task on hand to tackle. I am trying to write a script to
> automate the process of extracting the news items from Dow Jones news
> service. However, all the pages use javascript to execute the form
> submission. To see what I mean, go to http://djnewsplus.com and take a
> look at the login page. I guess this is their way of fending off scripting
> attack! Is there anyway  to beat the defense?

Wouldn't consider it a defense, since js is executed client side. You'll just have to
emulate the JavaScript-functions (i.e. figure out what exactly gets submitted) and
everything will work like a charm. 

Is a bit more work though, I agree.

Cheers,

-Christoph
--------------msEFD595E913BCDE6ED6B25641
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIHnwYJKoZIhvcNAQcCoIIHkDCCB4wCAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAaCC
BZ0wggJsMIIB1aADAgECAgMEfBEwDQYJKoZIhvcNAQEEBQAwgZIxCzAJBgNVBAYTAlpBMRUw
EwYDVQQIEwxXZXN0ZXJuIENhcGUxEjAQBgNVBAcTCUNhcGUgVG93bjEPMA0GA1UEChMGVGhh
d3RlMR0wGwYDVQQLExRDZXJ0aWZpY2F0ZSBTZXJ2aWNlczEoMCYGA1UEAxMfUGVyc29uYWwg
RnJlZW1haWwgUlNBIDIwMDAuOC4zMDAeFw0wMTAzMjgxMzA2NTFaFw0wMjAzMjgxMzA2NTFa
MDsxHzAdBgNVBAMTFlRoYXd0ZSBGcmVlbWFpbCBNZW1iZXIxGDAWBgkqhkiG9w0BCQEWCWN3
QGR3Yy5jaDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAt72bxF9v6Ym9py5JcxRsGiJl
qyyDgKdcZZJDZLorXu5bNjYz8eUQtCxuFdZyC6EbDJUNaghqngit95SHnvcH2+cyuqUzjRZr
pLbqGLJRE+hFq384a/+8Vmifm5fcRcQ0LWZU24ps28C2axice01D/aHB9hfG6Fw7jh8NqfVJ
rlsCAwEAAaMmMCQwFAYDVR0RBA0wC4EJY3dAZHdjLmNoMAwGA1UdEwEB/wQCMAAwDQYJKoZI
hvcNAQEEBQADgYEA1BIgS+i9rMOUcW6Cj62rfJr3KjwDr3PcH0MSRCocdJoYUhPwp5kiBNNk
ol6TZ02EBjWEEfWLnW7DZnKTlsrsjY3km6gJtOOh5vZnWMcQLpYsQQjgSJQvdV5teOYCMI4f
pkEZBfDvHrtgCFSo8TGvFqKkYH+7LQWq0I98qoOwv4cwggMpMIICkqADAgECAgEMMA0GCSqG
SIb3DQEBBAUAMIHRMQswCQYDVQQGEwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRIwEAYD
VQQHEwlDYXBlIFRvd24xGjAYBgNVBAoTEVRoYXd0ZSBDb25zdWx0aW5nMSgwJgYDVQQLEx9D
ZXJ0aWZpY2F0aW9uIFNlcnZpY2VzIERpdmlzaW9uMSQwIgYDVQQDExtUaGF3dGUgUGVyc29u
YWwgRnJlZW1haWwgQ0ExKzApBgkqhkiG9w0BCQEWHHBlcnNvbmFsLWZyZWVtYWlsQHRoYXd0
ZS5jb20wHhcNMDAwODMwMDAwMDAwWhcNMDIwODI5MjM1OTU5WjCBkjELMAkGA1UEBhMCWkEx
FTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3duMQ8wDQYDVQQKEwZU
aGF3dGUxHTAbBgNVBAsTFENlcnRpZmljYXRlIFNlcnZpY2VzMSgwJgYDVQQDEx9QZXJzb25h
bCBGcmVlbWFpbCBSU0EgMjAwMC44LjMwMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDe
MzKmY8cJJUU+0m54J2eBxdqIGYKXDuNEKYpjNSptcDz63K737nRvMLwzkH/5NHGgo22Y8cNP
omXbDfpL8dbdYaX5hc1VmjUanZJ1qCeu2HL5ugL217CR3hzpq+AYA6h8Q0JQUYeDPPA5tJtU
ihOH/7ObnUlmAC0JieyUa+mhaQIDAQABo04wTDApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMR
UHJpdmF0ZUxhYmVsMS0yOTcwEgYDVR0TAQH/BAgwBgEB/wIBADALBgNVHQ8EBAMCAQYwDQYJ
KoZIhvcNAQEEBQADgYEAcxtvJmWL/xU0S1liiu1EvknH6A27j7kNaiYqYoQfuIdjdBxtt88a
U5FL4c3mONntUPQ6bDSSrOaSnG7BIwHCCafvS65y3QZn9VBvLli4tgvBUFe17BzX7xe21Yib
t6KIGu05Wzl9NPy2lhglTWr0ncXDkS+plrgFPFL83eliA0gxggHKMIIBxgIBATCBmjCBkjEL
MAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3du
MQ8wDQYDVQQKEwZUaGF3dGUxHTAbBgNVBAsTFENlcnRpZmljYXRlIFNlcnZpY2VzMSgwJgYD
VQQDEx9QZXJzb25hbCBGcmVlbWFpbCBSU0EgMjAwMC44LjMwAgMEfBEwCQYFKw4DAhoFAKCB
hjAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0wMTA0MDIxNTQ4
MjdaMCMGCSqGSIb3DQEJBDEWBBRFifXA4BbiPb2PZ7MdLmX/DTYi3DAnBgkqhkiG9w0BCQ8x
GjAYMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMA0GCSqGSIb3DQEBAQUABIGAAQXY/lIPbRqM
nwJ/jQpKasHQeVf6yf2tmWX4EBODCXwdEbvGs1TGbqWgsq5kDjaYyIPk37Cm3cOSKEEQl4MY
G8I2Y17lRZuSCZc2qYOUOXmlFucdeMO496XjoqElGH/FR5yBY8mc+kUSh8WedyEyQi0XWwn2
8M3s43fdJDfDqfg=
--------------msEFD595E913BCDE6ED6B25641--