1 Users appreciate this thread.
Admin hole in security
carlos11 (2014-09-21 19:01:23)This is like seeing Lady Plaza naked.
Language is a tool for efficient communication. The internet is a tool for fast communication. Do not defy both intents by posting incoherent writing.
Leviathan (2014-09-21 21:47:23)I'm not sure if that is an insult, or an exclamation of astonishment.
I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
little5 (2014-09-22 10:14:44)So many people have done MySQL injections and DoS'd the site, it's not we've funny.
Leviathan (2014-09-22 17:29:59)But this page makes it easy to do so. I did an SQL injection for diagnostic purposes, and it found a keyword, and only had trouble detecting the database. Somebody with a fast computer or extreme patience could get in through /members.
EDIT: MySQL is a database, not an injection. and Dos is a coding language. You mean DDos.
2014-09-23 00:32:31
I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
/members/ is a directory.
Which file allows MySQL injection? (Please send via PM as this is a matter of security).
SomeLuigi is changing in 2015.
Leviathan (2014-09-27 02:17:18)It's not "MySQL" injection. MySQL is a database type, such as oracle, that allows for SQL injection. Anyways I sent the PM.
I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
gliycheyfox (2016-02-18 23:17:15)....You just made SQL injection easier for people by telling everyone it's MySQL :I
Old thread. I have to close this because it was bumped from a long time ago
This topic is closed, so you can not post a comment.
Back to forum: Error / Bug Reports
New registered users today: 7
Newest registered user: ElegantVulpes
So I was running some site diagnostics, and noticed that www.3dsplaza.com/members is open to everybody. As some of you may know, this is an Administration page, and is extremely vulnerable to SQL injection. As well as Ddos. I suggest restricting it to administrators only.
Thank you.