PDA

View Full Version : HSP V0.2 Release



DeejayMachoo$
05-11-2007, 10:31 PM
Habbo Site Panel - Version 0.2 {OpenSource}



There was a few bugs in Version 0.1, This is now Open Source so no more need for Zend Optimizer!


UPDATE LOG
Admin notes added.
Welcome message added.
New Habbo Style Layout.



DEMO
URL: http://mattx.org/demo
User: Habbox
Pass: demo

DOWNLOAD
URL: http://mattx.org/HSP_V0.2.zip

Puma
05-11-2007, 10:36 PM
it wont let me login

EDIT.. NVM is works now xD

--ss--
05-11-2007, 10:37 PM
Wow I like it , nice skin , you may want to have a skin changer / different skins up for download in the future for your next version :p

+rep

lolwut
05-11-2007, 10:38 PM
We could have a non-Habbo and a Habbo skin switcher in the next thing. Good?

Puma
05-11-2007, 10:39 PM
Looks great well done

DeejayMachoo$
05-11-2007, 10:39 PM
Wow I like it , nice skin , you may want to have a skin changer / different skins up for download in the future for your next version :p

+repThanks great idea, ill try and work it into 0.3

adamFTW
05-11-2007, 10:42 PM
It doesnt seem to show my username when I goto the login page?

chrisgocrazyH
05-11-2007, 10:44 PM
looks like PHP dj with more fetures lol BUT VERY NICE +rep will use!!

DeejayMachoo$
05-11-2007, 10:47 PM
looks like PHP dj with more fetures lol BUT VERY NICE +rep will use!!It Basically is :)

Invent
05-11-2007, 10:50 PM
A LOT of uncleaned vars.

DeejayMachoo$
05-11-2007, 10:51 PM
A LOT of uncleaned vars.

Ver 0.2.. We can sort this later :)

Jamieb
05-11-2007, 10:55 PM
Can we edit this?

adamFTW
05-11-2007, 10:56 PM
How come I cant see any of the usernames?

DeejayMachoo$
05-11-2007, 10:58 PM
Can we edit this?As long as the copyright doesnt get removed..

and adam im not sure ill look into it later allrite?

lolwut
05-11-2007, 11:01 PM
oh fgs simon you moan all the time at anything i made, just TRY to be nice, just a little teeny bit?

Jamieb
05-11-2007, 11:01 PM
what copyright ?

EDIT.. GOT IT

DeejayMachoo$
05-11-2007, 11:02 PM
what copyright ?

EDIT.. GOT IT
Habbo Site Panel is Powered by Habbo Site Panel and is Copyright to the devlopers Mattx.org , H! and Layout Designed by Luke1194

Invent
05-11-2007, 11:04 PM
oh fgs simon you moan all the time at anything i made, just TRY to be nice, just a little teeny bit?

How was I mean or not nice? I was simply letting you know about a major security risk in your panel..

DeejayMachoo$
05-11-2007, 11:06 PM
Please can you 2 keep your arguments to pm. Thanks :)

Jamieb
05-11-2007, 11:11 PM
WOO there isnt a nav.php file:S

edit got it./.

whats this


http://thebobbas.net/staffpanel/images/nav_top.png
Warning: include(inc/nav.php) [function.include]: failed to open stream: No such file or directory in /home/thebobba/public_html/staffpanel/login.php on line 89

Warning: include(inc/nav.php) [function.include]: failed to open stream: No such file or directory in /home/thebobba/public_html/staffpanel/login.php on line 89

Warning: include() [function.include]: Failed opening 'inc/nav.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/thebobba/public_html/staffpanel/login.php on line 89

DeejayMachoo$
05-11-2007, 11:16 PM
WOO there isnt a nav.php file:S

edit got it./.

whats this


http://thebobbas.net/staffpanel/images/nav_top.png
Warning: include(inc/nav.php) [function.include]: failed to open stream: No such file or directory in /home/thebobba/public_html/staffpanel/login.php on line 89

Warning: include(inc/nav.php) [function.include]: failed to open stream: No such file or directory in /home/thebobba/public_html/staffpanel/login.php on line 89

Warning: include() [function.include]: Failed opening 'inc/nav.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/thebobba/public_html/staffpanel/login.php on line 89Itz in the zip

Jamieb
05-11-2007, 11:39 PM
Thanks.. Is there a way to add more things to profle system?

DeejayMachoo$
06-11-2007, 12:04 AM
Ill add custom profile fields in the next version.

adamFTW
06-11-2007, 12:12 AM
Thanks for helping me out Matt.

Very nice panel. :)

DeejayMachoo$
06-11-2007, 12:14 AM
Second DEMO
http://habboboards.com/HSP/
User: demo
Pass: demo

Beau
06-11-2007, 05:10 AM
Good... But as Invent said, many many many security flaws.

Take this for instance:

http://img259.imageshack.us/img259/2120/scr159bcaaap2.png

That worked. Now, that code was fairly harmless, but if Javascript is working, it can easily be used to send the user to a site that logs their cookie information, or to a porn site etc.

Whenever you're going to be displaying something like that, escape it with htmlentities():




$var = htmlentities($news['newscontent']);



Will show HTML tags as the actual characters (won't convert them to HTML).

DeejayMachoo$
06-11-2007, 07:31 AM
Thanks ill work on adding to the next ver benzor

also +rep to all constructive critasisum (w/e its spelt)

Tomm
06-11-2007, 08:13 AM
This is highly insecure. I do not recommend you use it until the security issues are fixed. Input from POST and GET variables are being put directly into SQL queries. None of the input is cleaned for XSS or any other attack using javascript.

Beau
06-11-2007, 08:50 AM
This is highly insecure. I do not recommend you use it until the security issues are fixed. Input from POST and GET variables are being put directly into SQL queries. None of the input is cleaned for XSS or any other attack using javascript.

Unfortunately, Tom is right. And may I add, this is the same with most, DJ panels for release now. Developers should be making sure they are sanitizing both POST and GET inputs, escaping HTML when displaying data etc.

DeejayMachoo$
06-11-2007, 01:14 PM
Unfortunately, Tom is right. And may I add, this is the same with most, DJ panels for release now. Developers should be making sure they are sanitizing both POST and GET inputs, escaping HTML when displaying data etc.

Ok thanks for the comments and i will work with H! get try to get a Security fix out tonight.

lolwut
06-11-2007, 01:17 PM
Fair comments, I'll start editing the pages to do escape HTML and try to use mysql_real_escape_string(); more too. Thanks benzoenator and redtom ;)
For anyone who's wondering, the main difference between the 0.1 release and this one is that this isn't Zend encoded. Which means less work for me and Matt in the long run.

DJ-Louis
06-11-2007, 01:40 PM
Very nice.

RedCrisps
06-11-2007, 03:57 PM
Love it, however the navigation shows at the side without anyone being logged in :S

Luke
06-11-2007, 04:17 PM
yay my layout is on :)

Anyway, this is a bit unsecure as i see due to the javascripts.

When these are fixxed will be good though xD

iTechnical
06-11-2007, 04:21 PM
yay my layout is on :)

Anyway, this is a bit unsecure as i see due to the javascripts.

When these are fixxed will be good though xD

Mhm, agree'd

lolwut
06-11-2007, 04:44 PM
What Javascript. It doesn't even use any >_>
Now in the process of making alot of use of mysql_real_excape_string(); (:

Luke
06-11-2007, 04:48 PM
What Javascript. It doesn't even use any >_>
Now in the process of making alot of use of mysql_real_excape_string(); (:


I mean that you can use javacscript when poting news.

--ss--
06-11-2007, 04:50 PM
A fix to the javascript could be that you have to use certain BB codes and only the simple codes such as Bold , underline , image , link etc is allowed

lolwut
06-11-2007, 04:50 PM
*requires further explanation*
--ss--2; The news script doesn't even HAVE BBCode. :rolleyes:

Lilian
06-11-2007, 05:17 PM
View News redirects you to google whilst reading lol!

lolwut
06-11-2007, 07:29 PM
cool.
*really doesn't care*
*considers it spam*

MrCraig
06-11-2007, 08:21 PM
oh fgs simon you moan all the time at anything i made, just TRY to be nice, just a little teeny bit?

Dude, he did the same to my UserSystem v1, And im thanking him for it now,

Because if he hadnt said it, then i would be running 'The dodgiest panel on the net'

And v2 wouldnt be as good as it is now =]

Looks good frontend-wise, But code looks mangled srry.

LegendOfNoob
06-11-2007, 08:23 PM
gotta admit Cj's v2 rocked down the house with the features aswell as the secruity

lolwut
06-11-2007, 08:43 PM
Thanks for hijacking thread. >_>
For everyone's info; Security improvments being done right now. :]!
Technical side; mysql_real_escape_string() and strip_tags() being used on basically everything.
And we're not using hidden form fields atall now.

MrCraig
06-11-2007, 09:01 PM
Im not hijacking thread, just saying you should pay more attention to security.

:Edzy
06-11-2007, 10:20 PM
zended?

DeejayMachoo$
06-11-2007, 11:45 PM
zended?
no and

http://habboxforum.com/showthread.php?p=4095864

Want to hide these adverts? Register an account for free!