NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Programming
Reload this Page Security check please?

Programming PHP, Perl, Ruby on Rails, AJAX, HTML, XHTML, CSS, JavaScript, MySQL and any other coding topics.

Advanced Search


Closed Thread
 
LinkBack Thread Tools
Old 08-14-2006, 05:40 PM THREAD STARTER               #1 (permalink)
NamePros Member
Join Date: Jul 2006
Location: Gardendale, Texas
Posts: 48
Zhang is an unknown quantity at this point
 



Security check please?


For those of you who know, could you please check my site at http://www.easyshotz.com/ and see if you are able to find any security vulnerabilities? I'm using a php script that I'm totally unfamiliar with, and I want to make sure the site is secure before I start directing too much traffic to it.
__________________
www.affordablehostingdirect.com (Work in progress)
www.gimmeanotherbeer.com (Work in progress, not mine, my husband's concept!)
www.wow-tlc.com (Complete)
Zhang is offline  
Old 08-14-2006, 05:45 PM   #2 (permalink)
Dan
Buy my domains.
 
Dan's Avatar
Join Date: Feb 2006
Posts: 2,796
Dan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant future
 


Autism Autism Autism Autism Autism Autism Autism
I'm pretty sure that script is very secure, but I'm trying to do some stuff now.

edit:
It strips out anything after a " and 's do nothing.
You can't do anything like file.php.jpg, etc.

It's secure.
Last edited by Dan Friedman; 08-14-2006 at 05:52 PM.
Dan is offline  
Old 08-14-2006, 07:00 PM   #3 (permalink)
Eating Pie
 
iNod's Avatar
Join Date: Nov 2004
Location: Canada
Posts: 2,272
iNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud of
 


Special Olympics AIDS/HIV Cystic Fibrosis Save The Children Baby Health Cystic Fibrosis
The script is made by celeron dude and all security vulnerabilities have been reporting and fixed. I have checked most of the versions, they are all 100% secure. Though there is always new ways.

- Steve
__________________
I feel old.
iNod is offline  
Old 08-14-2006, 07:09 PM THREAD STARTER               #4 (permalink)
NamePros Member
Join Date: Jul 2006
Location: Gardendale, Texas
Posts: 48
Zhang is an unknown quantity at this point
 



Alrighty, thanks guys, I appreciate the reassurance.
__________________
www.affordablehostingdirect.com (Work in progress)
www.gimmeanotherbeer.com (Work in progress, not mine, my husband's concept!)
www.wow-tlc.com (Complete)
Zhang is offline  
Old 08-14-2006, 10:07 PM   #5 (permalink)
NamePros Regular
 
nick's Avatar
Join Date: Jun 2004
Location: Iowa City
Posts: 705
nick has much to be proud ofnick has much to be proud ofnick has much to be proud ofnick has much to be proud ofnick has much to be proud ofnick has much to be proud ofnick has much to be proud ofnick has much to be proud of
 


Save The Children
you need to use htmlspecialchars or something similiar to that function on the registration page
__________________
formally ninedogger
------
Want to talk to a stranger? -->| Click Here | TalkToAStranger.com | <-- Meet New Friends
nick is offline  
Old 08-14-2006, 11:56 PM   #6 (permalink)
Senior Member
 
Camron's Avatar
Join Date: Jan 2006
Location: Portland, Oregon
Posts: 2,102
Camron has much to be proud ofCamron has much to be proud ofCamron has much to be proud ofCamron has much to be proud ofCamron has much to be proud ofCamron has much to be proud ofCamron has much to be proud ofCamron has much to be proud ofCamron has much to be proud of
 



VA Tech Memorial 9/11/01 :: Never Forget Cancer Survivorship Child Abuse
It is very secure, but I do not like flat file scripts my self. I heard their was a turkish hacker which can destroy this script in a few clicks, check out CD's forum, it has his IP which you should block.
__________________
HostingFuze.com Premium Master Reseller Services | 99.9% Uptime Guaranteed SLA | Starting at $4.95/mo
Basic Reseller Hosting @ HostFz.com - Services starting as low as $1.95/mo!
Camron is offline  
Old 08-15-2006, 05:20 AM   #7 (permalink)
Dan
Buy my domains.
 
Dan's Avatar
Join Date: Feb 2006
Posts: 2,796
Dan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant futureDan has a brilliant future
 


Autism Autism Autism Autism Autism Autism Autism
Blocking IP's is pointless. It's not hard to change it, especially if he's any good at hacking.
Dan is offline  
Old 08-15-2006, 09:36 PM   #8 (permalink)
Eating Pie
 
iNod's Avatar
Join Date: Nov 2004
Location: Canada
Posts: 2,272
iNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud of
 


Special Olympics AIDS/HIV Cystic Fibrosis Save The Children Baby Health Cystic Fibrosis
Depends.. I know alot of sites (mainly web hosts) that are using IP DB's to block all IPs from Africa and the Middle east. Not that there is a problem with there it is just that there is 10 times more fraud orders than real order from those areas. Mainly Nigeria.

- Steve
__________________
I feel old.
iNod is offline  
Old 08-17-2006, 11:15 AM THREAD STARTER               #9 (permalink)
NamePros Member
Join Date: Jul 2006
Location: Gardendale, Texas
Posts: 48
Zhang is an unknown quantity at this point
 



I'm having to second guess the security on this...I can't seem to connect to the site anymore. I'm not sure if it's hacked or what. The information is still in the database, it should be functioning properly, but it's not even coming up.
__________________
www.affordablehostingdirect.com (Work in progress)
www.gimmeanotherbeer.com (Work in progress, not mine, my husband's concept!)
www.wow-tlc.com (Complete)
Zhang is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Liquid Web Smart Servers  
All times are GMT -7. The time now is 02:37 AM.

Managed Web Hosting by Liquid Web
Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger