Page 1 of 3 123 LastLast
Results 1 to 10 of 23
  1. #1

    Default I need a more secure dj panel

    Yeh, i use quickscriptz
    But i need a more secure one.
    Please help

  2. #2
    Join Date
    Mar 2008
    Location
    Swindon, UK
    Posts
    1,274
    Tokens
    187
    Habbo
    :Ltd

    Latest Awards:

    Default

    How secure can you be?
    Hi, names James. I am a web developer.

  3. #3
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    I quite like Kristall-Panel RC2. I have edited it alot though, so its more secure.

  4. #4

    Default

    the quickscriptz has been hacked 3 times
    lol
    Last edited by greggy23; 19-04-2008 at 11:51 AM.

  5. #5
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    Quote Originally Posted by greggy23 View Post
    the quickscriptz has been hacked 3 times
    lol
    I dont think its the panel, it will be your staff with passwords such as changeme.

    We have made it so our passwords cant be changeme. And when a Radio Manager adds an account, there password is randomly generated. Best way to make it secure

  6. #6
    Join Date
    Mar 2008
    Location
    Swindon, UK
    Posts
    1,274
    Tokens
    187
    Habbo
    :Ltd

    Latest Awards:

    Default

    Oh god, how does it get hacked though? LOL, I just checked "check.php" it sets a SESSION for a password? No wonder its insecure, I think the whole thing needs re-thinking but no offense to the creator.

    Quote Originally Posted by Jack120 View Post
    I dont think its the panel, it will be your staff with passwords such as changeme.

    We have made it so our passwords cant be changeme. And when a Radio Manager adds an account, there password is randomly generated. Best way to make it secure
    I just checked one source of it, and I think its insecure.

    PHP Code:
    $query mysql_query("SELECT username,djname,passwrd,rank,email FROM rp_users WHERE username = '$username'") or die(mysql_error());
    $row mysql_fetch_array($query);
    $_SESSION["rp_logged"] = TRUE;
    $_SESSION["rp_username"] = $row['username'];
    $_SESSION["rp_passwrd"] = $row['passwrd'];
    $_SESSION["rp_djname"] = $row['djname'];
    $_SESSION["rp_email"] = $row['email'];
    $_SESSION["rp_rank"] = $row['rank']; 
    Last edited by Protege; 19-04-2008 at 12:02 PM.
    Hi, names James. I am a web developer.

  7. #7
    Join Date
    Feb 2008
    Location
    Derby
    Posts
    305
    Tokens
    0

    Default

    Quote Originally Posted by DriftPanzy View Post
    Oh god, how does it get hacked though? LOL, I just checked "check.php" it sets a SESSION for a password? No wonder its insecure, I think the whole thing needs re-thinking but no offense to the creator.



    I just checked one source of it, and I think its insecure.

    PHP Code:
    $query mysql_query("SELECT username,djname,passwrd,rank,email FROM rp_users WHERE username = '$username'") or die(mysql_error());
    $row mysql_fetch_array($query);
    $_SESSION["rp_logged"] = TRUE;
    $_SESSION["rp_username"] = $row['username'];
    $_SESSION["rp_passwrd"] = $row['passwrd'];
    $_SESSION["rp_djname"] = $row['djname'];
    $_SESSION["rp_email"] = $row['email'];
    $_SESSION["rp_rank"] = $row['rank']; 
    So the panel can be hacked via that file?
    Win rares and lots more on this thread http://www.habboxforum.com/showthread.php?t=479892
    www.habbo-hc.com -LOOKING FOR STAFF

  8. #8
    Join Date
    Mar 2008
    Location
    Swindon, UK
    Posts
    1,274
    Tokens
    187
    Habbo
    :Ltd

    Latest Awards:

    Default

    Ever heard of session stealing? They publish the users password via a SESSION its like putting it on a file on your server and calling it index.html looooooool
    Hi, names James. I am a web developer.

  9. #9
    Join Date
    Feb 2008
    Location
    Derby
    Posts
    305
    Tokens
    0

    Default

    Quote Originally Posted by DriftPanzy View Post
    Ever heard of session stealing? They publish the users password via a SESSION its like putting it on a file on your server and calling it index.html looooooool
    Yeh but im just not sure exactly how it all works i mean i us cutenews but the person who hacked that didnt change anything he jus left a message saying delete search.php. I take it change.php with the dj panel works in the same way?
    Win rares and lots more on this thread http://www.habboxforum.com/showthread.php?t=479892
    www.habbo-hc.com -LOOKING FOR STAFF

  10. #10
    Join Date
    Mar 2008
    Location
    Swindon, UK
    Posts
    1,274
    Tokens
    187
    Habbo
    :Ltd

    Latest Awards:

    Default

    I dont understand, maybe hes using a PHP exploit?
    Hi, names James. I am a web developer.

Page 1 of 3 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •