[advanced search]
 

Go Back   NamePros.com > Discussion > Web Design & Development > Programming

Programming PHP, Perl, Ruby on Rails, AJAX, HTML, XHTML, CSS, JavaScript, MySQL and any other coding topics.


Closed Thread
 
LinkBack Thread Tools
Old 08-17-2006, 01:25 PM   #1 (permalink)
Account Closed
 
Join Date: Feb 2006
Posts: 272
52.00 NP$ (Donate)

DVBT is an unknown quantity at this point


Please test my sites security

Hi i am looking for you programmers to test out the security of my new site.

http://www.classpile.com/dev/taglinks/

The site is on a test server atm, thats why i want the security tested so i can have it as secure as possible for when i launch it

Please PM me your results.

regards
DVBT is offline  
Old 08-17-2006, 03:45 PM   #2 (permalink)
NamePros Regular
 
Noobie's Avatar
 
Join Date: Feb 2006
Location: Montreal, Quebec, Canada
Posts: 324
66.75 NP$ (Donate)

Noobie is on a distinguished road


It looks ok for me in FF but not in IE if you're using css shrink the size of your main div i think

Does the search work?
__________________
Goldkey.com is a scam
What's your BMI? | Timestamp Generator

Last edited by Noobie; 08-17-2006 at 03:48 PM. Reason: spelling
Noobie is offline  
Old 08-17-2006, 03:53 PM   #3 (permalink)
Account Closed
 
Join Date: Feb 2006
Posts: 272
52.00 NP$ (Donate)

DVBT is an unknown quantity at this point


what about any security issues. Get any of them?
DVBT is offline  
Old 08-17-2006, 07:58 PM   #4 (permalink)
NamePros Regular
 
Noobie's Avatar
 
Join Date: Feb 2006
Location: Montreal, Quebec, Canada
Posts: 324
66.75 NP$ (Donate)

Noobie is on a distinguished road


I did try sql injection on your login ...
but nothing to test if nothing is functioning ?
__________________
Goldkey.com is a scam
What's your BMI? | Timestamp Generator
Noobie is offline  
Old 08-18-2006, 09:30 AM   #5 (permalink)
Account Closed
 
Join Date: Feb 2006
Posts: 272
52.00 NP$ (Donate)

DVBT is an unknown quantity at this point


nope everything is functioning apart from the search box atm

regards
DVBT is offline  
Old 08-18-2006, 10:22 AM   #6 (permalink)
Eating Pie
 
iNod's Avatar
 
Join Date: Nov 2004
Location: Canada
Posts: 2,289
126.05 NP$ (Donate)

iNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud of

Special Olympics AIDS/HIV Cystic Fibrosis Save The Children Baby Health Cystic Fibrosis
Your sites Login box doesn't seem to allow SQL interjections so a good for that. I checked a few things and they all are a good. So I do not see any clearly visable security issues.

- Steve
__________________
I feel old.
iNod is offline  
Old 08-18-2006, 12:23 PM   #7 (permalink)
Account Closed
 
Join Date: Feb 2006
Posts: 272
52.00 NP$ (Donate)

DVBT is an unknown quantity at this point


Quote:
Originally Posted by iNod
Your sites Login box doesn't seem to allow SQL interjections so a good for that. I checked a few things and they all are a good. So I do not see any clearly visable security issues.

- Steve
thanks for letting me no steve

rep points added
DVBT is offline  
Old 08-18-2006, 12:44 PM   #8 (permalink)
NamePros Regular
 
baxter's Avatar
 
Join Date: Apr 2006
Posts: 289
1,990.00 NP$ (Donate)

baxter is a jewel in the roughbaxter is a jewel in the roughbaxter is a jewel in the rough

Ethan Allen Fund Save The Children
http://www.classpile.com/dev/taglinks/index.php?p=addfavorite&id='

gives me information on your sql user and path information. I didn't really have a lot of time to test anything else

Cheers
baxter is offline  
Old 08-18-2006, 01:18 PM   #9 (permalink)
Account Closed
 
Join Date: Feb 2006
Posts: 272
52.00 NP$ (Donate)

DVBT is an unknown quantity at this point


Quote:
Originally Posted by baxter
http://www.classpile.com/dev/taglinks/index.php?p=addfavorite&id='

gives me information on your sql user and path information. I didn't really have a lot of time to test anything else

Cheers
is that importantm does that mean somebody can use that information to hack the website?
DVBT is offline  
Old 08-18-2006, 03:31 PM   #10 (permalink)
NamePros Regular
 
baxter's Avatar
 
Join Date: Apr 2006
Posts: 289
1,990.00 NP$ (Donate)

baxter is a jewel in the roughbaxter is a jewel in the roughbaxter is a jewel in the rough

Ethan Allen Fund Save The Children
Yes and no. It gives me information as to if say I come across a cpanel login I know what username to try. If I come accross a vulnerability with file viewing I know the exact path to your site from the server and can backtrace from there. If your host allows connections from other networks by default I could gain access to your mysql database especially since its not using a password.

All this can be fixed by simply adding intval() to sanitize it into a number

Cheers,

Bax
baxter is offline  
Old 08-18-2006, 03:55 PM   #11 (permalink)
Account Closed
 
Join Date: Feb 2006
Posts: 272
52.00 NP$ (Donate)

DVBT is an unknown quantity at this point


thanks for that baxter.

Rep points added
DVBT is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Site Sponsors
Advertise your business at NamePros

All times are GMT -7. The time now is 07:50 AM.


Powered by: vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Template-Modifications by TMS
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85