NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Programming
Reload this Page Please test my sites security

Programming PHP, Perl, Ruby on Rails, AJAX, HTML, XHTML, CSS, JavaScript, MySQL and any other coding topics.

Advanced Search


Closed Thread
 
LinkBack Thread Tools
Old 08-17-2006, 02:25 PM THREAD STARTER               #1 (permalink)
Account Closed
Join Date: Feb 2006
Posts: 272
DVBT is an unknown quantity at this point
 



Please test my sites security


Hi i am looking for you programmers to test out the security of my new site.

http://www.classpile.com/dev/taglinks/

The site is on a test server atm, thats why i want the security tested so i can have it as secure as possible for when i launch it

Please PM me your results.

regards
DVBT is offline  
Old 08-17-2006, 04:45 PM   #2 (permalink)
NamePros Regular
 
Noobie's Avatar
Join Date: Feb 2006
Location: Montreal, Quebec, Canada
Posts: 324
Noobie is on a distinguished road
 



It looks ok for me in FF but not in IE if you're using css shrink the size of your main div i think

Does the search work?
__________________
Goldkey.com is a scam
What's your BMI? | Timestamp Generator
Last edited by Noobie; 08-17-2006 at 04:48 PM. Reason: spelling
Noobie is offline  
Old 08-17-2006, 04:53 PM THREAD STARTER               #3 (permalink)
Account Closed
Join Date: Feb 2006
Posts: 272
DVBT is an unknown quantity at this point
 



what about any security issues. Get any of them?
DVBT is offline  
Old 08-17-2006, 08:58 PM   #4 (permalink)
NamePros Regular
 
Noobie's Avatar
Join Date: Feb 2006
Location: Montreal, Quebec, Canada
Posts: 324
Noobie is on a distinguished road
 



I did try sql injection on your login ...
but nothing to test if nothing is functioning ?
__________________
Goldkey.com is a scam
What's your BMI? | Timestamp Generator
Noobie is offline  
Old 08-18-2006, 10:30 AM THREAD STARTER               #5 (permalink)
Account Closed
Join Date: Feb 2006
Posts: 272
DVBT is an unknown quantity at this point
 



nope everything is functioning apart from the search box atm

regards
DVBT is offline  
Old 08-18-2006, 11:22 AM   #6 (permalink)
Eating Pie
 
iNod's Avatar
Join Date: Nov 2004
Location: Canada
Posts: 2,272
iNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud of
 


Special Olympics AIDS/HIV Cystic Fibrosis Save The Children Baby Health Cystic Fibrosis
Your sites Login box doesn't seem to allow SQL interjections so a good for that. I checked a few things and they all are a good. So I do not see any clearly visable security issues.

- Steve
__________________
I feel old.
iNod is offline  
Old 08-18-2006, 01:23 PM THREAD STARTER               #7 (permalink)
Account Closed
Join Date: Feb 2006
Posts: 272
DVBT is an unknown quantity at this point
 



Originally Posted by iNod
Your sites Login box doesn't seem to allow SQL interjections so a good for that. I checked a few things and they all are a good. So I do not see any clearly visable security issues.
????: NamePros.com http://www.namepros.com/programming/228724-please-test-my-sites-security.html

- Steve
thanks for letting me no steve

rep points added
DVBT is offline  
Old 08-18-2006, 01:44 PM   #8 (permalink)
NamePros Regular
 
baxter's Avatar
Join Date: Apr 2006
Posts: 363
baxter is just really nicebaxter is just really nicebaxter is just really nicebaxter is just really nice
 


Ethan Allen Fund Save The Children
http://www.classpile.com/dev/taglinks/index.php?p=addfavorite&id='

gives me information on your sql user and path information. I didn't really have a lot of time to test anything else

Cheers
baxter is offline  
Old 08-18-2006, 02:18 PM THREAD STARTER               #9 (permalink)
Account Closed
Join Date: Feb 2006
Posts: 272
DVBT is an unknown quantity at this point
 



Originally Posted by baxter
http://www.classpile.com/dev/taglinks/index.php?p=addfavorite&id='
????: NamePros.com http://www.namepros.com/showthread.php?t=228724

gives me information on your sql user and path information. I didn't really have a lot of time to test anything else

Cheers
is that importantm does that mean somebody can use that information to hack the website?
DVBT is offline  
Old 08-18-2006, 04:31 PM   #10 (permalink)
NamePros Regular
 
baxter's Avatar
Join Date: Apr 2006
Posts: 363
baxter is just really nicebaxter is just really nicebaxter is just really nicebaxter is just really nice
 


Ethan Allen Fund Save The Children
Yes and no. It gives me information as to if say I come across a cpanel login I know what username to try. If I come accross a vulnerability with file viewing I know the exact path to your site from the server and can backtrace from there. If your host allows connections from other networks by default I could gain access to your mysql database especially since its not using a password.

All this can be fixed by simply adding intval() to sanitize it into a number

Cheers,

Bax
baxter is offline  
Old 08-18-2006, 04:55 PM THREAD STARTER               #11 (permalink)
Account Closed
Join Date: Feb 2006
Posts: 272
DVBT is an unknown quantity at this point
 



thanks for that baxter.

Rep points added
DVBT is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Liquid Web Smart Servers  
All times are GMT -7. The time now is 05:02 AM.

Managed Web Hosting by Liquid Web
Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger