Welcome to WebmasterWorld Guest from 54.226.246.160

Forum Moderators: brotherhood of lan & mack

Message Too Old, No Replies

Hitslink Code Verification

Is the code is verified by the webmasters

     

bilalseo

2:47 pm on Aug 27, 2008 (gmt 0)

5+ Year Member



Hello,

I'm here to ask you something about hitslinkdotcom. I have installed the code over the pages but found something dangerous in it. The code has some issues. I'd like to ask regarding hitslink script that is being given for web tracking.


<!-- www.hitslink.com/ web tools statistics hit counter code -->

<script type="text/javascript" id="wa_u"></script>

<script type="text/javascript">//<![CDATA[

wa_account="928B9D9CCECD"; wa_location=26;

wa_pageName=location.pathname; // you can customize the page name here

document.cookie='__support_check=1';wa_hp='http';

wa_rf=document.referrer;wa_sr=window.location.search;

wa_tz=new Date();if(location.href.substr(0,6).toLowerCase()=='https:')

wa_hp='https';wa_data='&an='+escape(navigator.appName)+

'&sr='+escape(wa_sr)+'&ck='+document.cookie.length+

'&rf='+escape(wa_rf)+'&sl='+escape(navigator.systemLanguage)+

'&av='+escape(navigator.appVersion)+'&l='+escape(navigator.language)+

'&pf='+escape(navigator.platform)+'&pg='+escape(wa_pageName);

wa_data=wa_data+'&cd='+

screen.colorDepth+'&rs='+escape(screen.width+ ' x '+screen.height)+

'&tz='+wa_tz.getTimezoneOffset()+'&je='+ navigator.javaEnabled();

wa_img=new Image();wa_img.src=wa_hp+'://counter.hitslink.com/statistics.asp'+

'?v=1&s='+wa_location+'&eacct='+wa_account+wa_data+'&tks='+wa_tz.getTime();

document.getElementById('wa_u').src=wa_hp+'://counter.hitslink.com/track.js'; //]]>

</script>

<!-- End www.hitslink.com/ statistics web tools hit counter code -->

</body>

This value (&an) is used in it for passing a single value to a varibale "an" but what is the meaning if it is uses with "&" sign. I have also seen there that there is another variable used to extract cookies (document.cookie) ... I want to ask you that for which purpose it is used. If it is used for getting our site client cookie, it could be harmed, and or if it is used to stay long on the website and if you again click on any webpage of hitslink, so it never ask you to relogin.

Thanks

bilal

bilalseo

11:20 pm on Sep 26, 2008 (gmt 0)

5+ Year Member



:(

brotherhood of LAN

4:58 pm on Sep 29, 2008 (gmt 0)

WebmasterWorld Administrator brotherhood_of_lan is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month



is there no mention in their documentation?

mikeyb

10:12 am on Oct 1, 2008 (gmt 0)

10+ Year Member



&an is a querystring parameter in the URL the data is posted to, just as in any URL www.example.com/something.asp?this=1&that=2
 

Featured Threads

Hot Threads This Week

Hot Threads This Month