Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 32
  1. #11
    Join Date
    Aug 2005
    Location
    East London
    Posts
    2,578
    Tokens
    0

    Latest Awards:

    Default

    PM me your msn

  2. #12
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    PHP Code:
        while($furn mysql_fetch_array($selectfurni))
        {
        echo(
    '<a href="furni.php?mode=buy&id='.$furn[id].'"><img src="'.$furn[url].'" alt="Cost: '.$furn[price].' Credits" /></a>');
        }
        }
        }
        
        
        if(
    $mode==buy)
        {
        
    $checkcreds mysql_query("select * from usr_users where username = '$_SESSION[usr_name]'");
        
    $user mysql_fetch_array($checkcreds);
        
    $selectfurni mysql_query("select * from usr_furnidb where id = '$id'"); 
    That is VERY insecure.

    Infact the whole thing is.

    You need to research var cleaning more.

  3. #13
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    You did no cleaning on selection/drop down menus?

    You MUST do satisfactory cleaning on ALL data that can be modified by the user.

    I don't suppose you know that you can easily change the values of a dropdown box by typeing javascript (Prefixed by javascript in the address bar while viewing the site?

    Quote Originally Posted by Cj555 View Post
    Emailer can be turned off for now, and i think default is set to off. u got any ideas how to fix it tho?

    +

    What vars arent cleaned? I know i didnt do most of the admin ones or select ones.

    Thanks for advice tho :]

  4. #14
    Join Date
    Jul 2006
    Location
    Athens
    Posts
    842
    Tokens
    0

    Default

    There are many flaws of which i can see including the one's simon mentioned.

    Also please use Hyphens and quote marks when using databse variables/Database queries and more... much easier to read and also use spaces

    I also reccomend you use
    PHP Code:
    <?php ?>
    instead of
    PHP Code:
    <? ?>


  5. #15
    Join Date
    May 2007
    Posts
    10,481
    Tokens
    3,140

    Latest Awards:


  6. #16
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    Plus, yes I know its a definition, but why copy my project name (Project: UserSystem, www.usersystem.net)?

  7. #17
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Tomm View Post
    Plus, yes I know its a definition, but why copy my project name (Project: UserSystem, www.usersystem.net)?

    Exactly for the reason you said, it is a usersystem...

    Im not trying to copy your project name

    +

    Simon, Yh, i will read up on var cleaning, dont know alot about security.

    Thanks Anyways
    Coming and going...
    Highers are getting the better of me

  8. #18
    Join Date
    Jul 2006
    Location
    Athens
    Posts
    842
    Tokens
    0

    Default

    Quote Originally Posted by Cj555 View Post
    Exactly for the reason you said, it is a usersystem...

    Im not trying to copy your project name

    +

    Simon, Yh, i will read up on var cleaning, dont know alot about security.

    Thanks Anyways
    So why release something that needs security


  9. #19
    Join Date
    Jul 2007
    Location
    Swindon
    Posts
    990
    Tokens
    125

    Default

    Sorry if im off topic but tomm is ures still avalible to download,
    back on topic there are too many security holes for what im wanting for sorry cj555

  10. #20
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    Also learn about seperating your layers, you should not have your presentation layer mixed up with your application layer & data layer.

    Quote Originally Posted by Cj555 View Post
    Exactly for the reason you said, it is a usersystem...

    Im not trying to copy your project name

    +

    Simon, Yh, i will read up on var cleaning, dont know alot about security.

    Thanks Anyways
    Quote Originally Posted by Eccentric View Post
    Sorry if im off topic but tomm is ures still avalible to download,
    back on topic there are too many security holes for what im wanting for sorry cj555
    Should be, do a quick search. However I can't remember if I hosted it on www.usersystem.net because if I did you'll need to wait for me to complete my server move (Moving to my new shiny server running Plesk)
    Last edited by Tomm; 08-09-2007 at 07:46 PM.

Page 2 of 4 FirstFirst 1234 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •