appteam-nith / hillffair2k18 Goto Github PK
View Code? Open in Web Editor NEWOfficial App for Hillf'fair 2K18 NITH.
License: GNU General Public License v3.0
Official App for Hillf'fair 2K18 NITH.
License: GNU General Public License v3.0
Try wrapping this up by Saturday.
Work on separate branches
Don't work on master branch
Don't waste time on UI. We just want implementation
sorry for posting it here , it is for the app of latest eir , but you guys removed it so ....
(wise decision btw)
hey ! you guys changed the implementation , which might have removed the db wipeout threat and
thats a good thing . i guess you also tweaked /User handler , but with all respect ,
there are still some loop holes and traversing is still possible
for example this link .
http://api.hillffair.com/User/5'%20OR%201=1%20--'
this statement will give you top row of the table
now you have data of first person
now you need to select every one else , but the first person
say its firebase_id is 0akwYovxZnf8h6Ja12gj28OzWEr1
now you need to select every body who is not first person
( 5 ' OR (1=1 AND firebase_id != "0akwYovxZnf8h6Ja12gj28OzWEr1" ))
which is just like adding inner boolian operations
now you have 2 person's data
now do the same to get the third one , select everybody who is not first and not second
just like that ! ezpz .
but later ,i found that "/leaderboard" also does the same thing . which gives me feeling dat "content security" is NOT the perpose app and as it is a intercollege project it is not even
necessary (but still i suggest , we should try our best to make our product standouu )
still i liked traversing thingy i made :P (seriously i made it myself), and also plz dont hate me , ill NOT try to do any unethical thing with the app . app is yours and yours only <3 .
tell me if i should delete this or not , or in case you want me to stop interfering with your club's decision !?
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.