[Website] AltairCMS! | Updated with steps to add new page

Page 11 of 17 FirstFirst ... 34567891011121314151617 LastLast
Results 151 to 165 of 246
  1. #151
    Apprentice namek303 is offline
    MemberRank
    Nov 2010 Join Date
    19Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Out of all the flaws on AltairCMS that i've been fixing. I recommend you fix the "GET" variable issue.

    Because if the "GET" info is not a number then do a check and make it do something else. for example if the "Get" variable is not a number or is INVALID make it by default equal 1. (doing this will fix the problem)

    Here is an example. replace your link for your AltairCMS page with this.


    Code:
    http://(YOUR WEBSITE FOR ALTAIR CMS HERE)/?page=index&id=<script>alert('hacked by namek303')</script>

    this security flaw will allow a user to actually make a cookie stealer. and all he needs to do is make a admin visit a page with the cookie stealer hidden on it. and boom he has the admin's cookies. and he replaces the Admin cookies with his and now hes a admin on the site. lots of damage that can be done for people that really customized it.

    the damage that he can do includes, making a notice or announcement that causes harm. (embedding the cookie grabber in an announcement, testing for sql injection using the announcement, making a redirect to another site from announcement, defacing the site from announcement, making comments from announcements that are inappropriate to name a few options)

    I really like this CMS and been working alot with it. Let me know how that works out or if u cant figure out how to fix it for you. (by fixing this you eliminate the biggest security flaw on the site)

  2. #152
    Apprentice zoopie is offline
    MemberRank
    Apr 2010 Join Date
    11Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    ok i followed all the steps and rename install to install.lock and i go to localhost and the page says
    Oops!This link appears to be broken
    URL: localhost/install/install.php

  3. #153
    Account Upgraded | Title Enabled! AuroX is offline
    MemberRank
    Sep 2008 Join Date
    1,431Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Once you've renamed it, go to http://localhost/index.php

  4. #154
    Member okfolife123 is offline
    MemberRank
    Jun 2010 Join Date
    56Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    i do and it redirects me to localhost/install/install.php

  5. #155
    Account Upgraded | Title Enabled! linkdamasta is offline
    MemberRank
    Oct 2009 Join Date
    280Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Yep. Epic fail. Even after you follow the instructions it tries to take you to install.php, and since you renamed it it just returns a 404 message.

    Edit:
    I named it install.lock, but it kept the PHP extension. Might want to clarify that you need to make sure to remove the extension.
    Last edited by linkdamasta; 11-12-10 at 07:27 PM.

  6. #156
    Account Upgraded | Title Enabled! AuroX is offline
    MemberRank
    Sep 2008 Join Date
    1,431Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    It must be a lock extension. If it is a php extension, then delete it > Open notepad> leave it blank > File>Save As > name ="install.lock" > File type: all files. put it into your install folder and you're done. I noticed his thing as vista and windows 7 won't change the extension for you when you edit it.

  7. #157
    Member okfolife123 is offline
    MemberRank
    Jun 2010 Join Date
    56Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Thnx and one more thing i cant find out how to add notice is the admin page or do i do it from Database. if database which table. if admin page what url. ty

  8. #158
    Account Upgraded | Title Enabled! AuroX is offline
    MemberRank
    Sep 2008 Join Date
    1,431Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Go to accounts table in SQL, find the desired account u want and set the admin column to 1. Then login at the control panel and you'll be redirected into the admin page.

  9. #159
    至死不渝 noviceboy55 is offline
    MemberRank
    Dec 2008 Join Date
    SingaporeLocation
    708Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Can someone give me an example of how to add the GAMEUP, NOTICE, END, PRIZE, INFO images in the news/events section in front of a line of text?

    Sry if this bumped a 2 weeks old tread :P

    @Yenpooh : maybe u can add a few lines in the cms event.php with image enabled such that people knows how to add it o:
    Last edited by noviceboy55; 27-12-10 at 09:34 AM.

  10. #160
    OFWGK†∆ joellol is offline
    MemberRank
    Apr 2008 Join Date
    HollandLocation
    479Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    When i do the .lock thing i end up if i go to the localhost directory i get redirected to localhost/install/install.php and then links me to google to search something

  11. #161
    Apprentice Sanctuality is offline
    MemberRank
    Dec 2010 Join Date
    5Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Yeah this is not working at all this = fail

  12. #162
    Account Upgraded | Title Enabled! AuroX is offline
    MemberRank
    Sep 2008 Join Date
    1,431Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    I've posted 2~3 post regarding the .lock stuffs, its not my problem, its your windows that doesn't change the extension. So you'll have to manually create a lock file.

  13. #163
    8===D Hubba is offline
    MemberRank
    Jan 2009 Join Date
    CanadaLocation
    1,009Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Added to library..

  14. #164
    Apprentice vgun999 is offline
    MemberRank
    Dec 2010 Join Date
    20Posts

    Re: [Website] AltairCMS!

    Quote Originally Posted by yenpooh View Post
    I have seen some of the computers which when you edit install.php to install.lock, it will still remains as install.lock.php

    To fix that I suggest you to open notepad, Leave it blank and Save as "install.lock" and the Save as type select"All files" and put the install.lock into your install folder.
    thank you that helped me :D

  15. #165
    Account Upgraded | Title Enabled! Expedia is offline
    MemberRank
    Nov 2009 Join Date
    884Posts

    Re: [Website] AltairCMS! | Updated with steps to add new page

    Quote Originally Posted by Hubba View Post
    Added to library..
    No one cares. There's a reason why it's locked up, but I guess Hubba-people are too stupid to realize it.



Advertisement