![]() |
|
#11
|
|||
|
|||
|
Quote:
Last edited by coder0403 : 03-04-2010 at 09:11 AM. |
|
#12
|
|||
|
|||
|
You are going wrong way of the main topic now. Just recheck my posts. Maybe my English so bad. Sorry for this.
|
|
#13
|
|||
|
|||
|
Quote:
The point I am trying to make here is that Users need to secure their scripts so that html code/queries cannot be appended to the URI string. The only reason those urls as mentioned in post #1 "work" is because they exploit a vulnerability in the script. They should not work, and should be 403 Forbidden. As for why would some one who hacked and gained access, want to further run codes and exploits/queries/JS/HTML thats because they can continue their "backdoor" access and do with your site whatever they want- from using it as a botnet/spamming/or to upload malicious malware/viruses/spyware and use it to further infect others- the options and reasons are endless. See this for one such vulnerability (in case you missed in my last edited post):
__________________
www.havocarcade.com | GSS 4/4.5 fixes/plugins/mods/tweaks/free themes/content | Havoc XFS | Gamers Lounge Last edited by rive0108 : 03-04-2010 at 06:38 PM. |
|
#14
|
|||
|
|||
|
In the end though, to close this-
The <a href/> anchor tags/db query for the nested Category Links in Admin/Media (and via address bar) WILL NOT function in the GSS 4.5 version due to the hardening of the mysql_real_escape_string, and the mysql_real_escape_string(strip_tags), and other security improvements. So, regardless of Coder0403's view on this issue, The new script version will break these, and prevent the html/query from being attached to the URI. It will result in a 403 Forbidden. I have made sure of that. These links in admin/media will be fixed and rewritten to properly call a db query function You can see the result here of how it will be: http://www.havocarcade.com/admin/ind...=sqlacces s-do
__________________
www.havocarcade.com | GSS 4/4.5 fixes/plugins/mods/tweaks/free themes/content | Havoc XFS | Gamers Lounge Last edited by rive0108 : 03-04-2010 at 11:08 AM. |
|
#15
|
|||
|
|||
|
Okay, thank rive0108. Please remove the site above that you uploaded remview.
|
|
#16
|
|||
|
|||
|
I uploaded nothing
__________________
www.havocarcade.com | GSS 4/4.5 fixes/plugins/mods/tweaks/free themes/content | Havoc XFS | Gamers Lounge |
|
#17
|
|||
|
|||
|
Folks, Its good to have a friendly debate on the vulnerable possiblities. Its all for good so that the community is updated on the risks involved.
Anyways, i feel we should not take this discussion further as the community is now well aware of the risk involved. ![]() |
![]() |
| Thread Tools | |
| Display Modes | |
|
|