[Help] DMNCMS Injections

Results 1 to 9 of 9
  1. #1
    Apprentice MaF1oZo is offline
    MemberRank
    Oct 2016 Join Date
    19Posts

    ! [Help] DMNCMS Injections

    Hi all,who know any dmncms holes,for sql inj and write how to fix it?i read today that some hole at market,is it true?


  2. #2
    Trafalgar D. Water Law Dope Boy One is offline
    ModeratorRank
    Jun 2005 Join Date
    HellasLocation
    1,223Posts

    Re: [Help] DMNCMS Injections

    Quote Originally Posted by MaF1oZo View Post
    Hi all,who know any dmncms holes,for sql inj and write how to fix it?i read today that some hole at market,is it true?
    be specific, on what version? on the cracked one or the premium?

  3. #3
    Apprentice MaF1oZo is offline
    MemberRank
    Oct 2016 Join Date
    19Posts

    Re: [Help] DMNCMS Injections

    premium 1.1.8

  4. #4
    Enthusiast Zaseth is offline
    MemberRank
    Oct 2018 Join Date
    The NetherlandsLocation
    31Posts

    Re: [Help] DMNCMS Injections

    You should make sure every query is prepared and every query using user input data should be escaped and checked for regex.

  5. #5
    Apprentice MaF1oZo is offline
    MemberRank
    Oct 2016 Join Date
    19Posts

    Re: [Help] DMNCMS Injections

    4 time my db,ports are close.From server too can't drop db,only site..forum at another hosting.any ideas?

  6. #6
    Trafalgar D. Water Law Dope Boy One is offline
    ModeratorRank
    Jun 2005 Join Date
    HellasLocation
    1,223Posts

    Re: [Help] DMNCMS Injections

    Quote Originally Posted by MaF1oZo View Post
    Hi all,who know any dmncms holes,for sql inj and write how to fix it?i read today that some hole at market,is it true?
    is it on market between characters or the shop on website?

  7. #7
    Enthusiast Zaseth is offline
    MemberRank
    Oct 2018 Join Date
    The NetherlandsLocation
    31Posts

    Re: [Help] DMNCMS Injections

    If your stuff is written in PHP, put in every .php file using MySQL the following line after the beginning of the script:

    PHP Code:
    error_reporting(-1); 
    This will print any error. Do note that everyone can see those errors. Let us know what errors you're getting.

  8. #8
    Account Upgraded | Title Enabled! solarismu is offline
    MemberRank
    May 2017 Join Date
    219Posts

    Re: [Help] DMNCMS Injections

    Quote Originally Posted by Zaseth View Post
    If your stuff is written in PHP, put in every .php file using MySQL the following line after the beginning of the script:
    PHP Code:
    error_reporting(-1); 
    This will print any error. Do note that everyone can see those errors. Let us know what errors you're getting.
    Sql injections are not errors. You will catch nothing in error log. Try to log all sql queries executed, and see what happened
    Last edited by solarismu; 20-10-18 at 02:12 AM.

  9. #9
    Enthusiast Zaseth is offline
    MemberRank
    Oct 2018 Join Date
    The NetherlandsLocation
    31Posts

    Re: [Help] DMNCMS Injections

    @solarismu

    Every MySQL error is captured. When you put an apostrophe in the query, it'll always generate an error. That's why OP should put an apostrophe wherever he can in-site and use a vulnerability scanner for PoC.



Advertisement