homepage Welcome to WebmasterWorld Guest from 54.227.41.242
register, free tools, login, search, pro membership, help, library, announcements, recent posts, open posts,
Become a Pro Member

Visit PubCon.com
Home / Forums Index / WebmasterWorld / New To Web Development
Forum Library, Charter, Moderators: brotherhood of lan & mack

New To Web Development Forum

    
Hitslink Code Verification
Is the code is verified by the webmasters
bilalseo




msg:3732425
 2:47 pm on Aug 27, 2008 (gmt 0)

Hello,

I'm here to ask you something about hitslinkdotcom. I have installed the code over the pages but found something dangerous in it. The code has some issues. I'd like to ask regarding hitslink script that is being given for web tracking.


<!-- www.hitslink.com/ web tools statistics hit counter code -->

<script type="text/javascript" id="wa_u"></script>

<script type="text/javascript">//<![CDATA[

wa_account="928B9D9CCECD"; wa_location=26;

wa_pageName=location.pathname; // you can customize the page name here

document.cookie='__support_check=1';wa_hp='http';

wa_rf=document.referrer;wa_sr=window.location.search;

wa_tz=new Date();if(location.href.substr(0,6).toLowerCase()=='https:')

wa_hp='https';wa_data='&an='+escape(navigator.appName)+

'&sr='+escape(wa_sr)+'&ck='+document.cookie.length+

'&rf='+escape(wa_rf)+'&sl='+escape(navigator.systemLanguage)+

'&av='+escape(navigator.appVersion)+'&l='+escape(navigator.language)+

'&pf='+escape(navigator.platform)+'&pg='+escape(wa_pageName);

wa_data=wa_data+'&cd='+

screen.colorDepth+'&rs='+escape(screen.width+ ' x '+screen.height)+

'&tz='+wa_tz.getTimezoneOffset()+'&je='+ navigator.javaEnabled();

wa_img=new Image();wa_img.src=wa_hp+'://counter.hitslink.com/statistics.asp'+

'?v=1&s='+wa_location+'&eacct='+wa_account+wa_data+'&tks='+wa_tz.getTime();

document.getElementById('wa_u').src=wa_hp+'://counter.hitslink.com/track.js'; //]]>

</script>

<!-- End www.hitslink.com/ statistics web tools hit counter code -->

</body>

This value (&an) is used in it for passing a single value to a varibale "an" but what is the meaning if it is uses with "&" sign. I have also seen there that there is another variable used to extract cookies (document.cookie) ... I want to ask you that for which purpose it is used. If it is used for getting our site client cookie, it could be harmed, and or if it is used to stay long on the website and if you again click on any webpage of hitslink, so it never ask you to relogin.

Thanks

bilal

 

bilalseo




msg:3753108
 11:20 pm on Sep 26, 2008 (gmt 0)

:(

brotherhood of LAN




msg:3754662
 4:58 pm on Sep 29, 2008 (gmt 0)

is there no mention in their documentation?

mikeyb




msg:3756456
 10:12 am on Oct 1, 2008 (gmt 0)

&an is a querystring parameter in the URL the data is posted to, just as in any URL www.example.com/something.asp?this=1&that=2

Global Options:
 top home search open messages active posts  
 

Home / Forums Index / WebmasterWorld / New To Web Development
rss feed

All trademarks and copyrights held by respective owners. Member comments are owned by the poster.
Home ¦ Free Tools ¦ Terms of Service ¦ Privacy Policy ¦ Report Problem ¦ About ¦ Library ¦ Newsletter
WebmasterWorld is a Developer Shed Community owned by Jim Boykin.
© Webmaster World 1996-2014 all rights reserved