Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19

Thread: Php help

  1. #11
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default

    If it is, an $admin variable wouldn't be needed, as we'd already know it was in the admin control area.
    How could this hapen to meeeeeeeeeeeeeee?lol.

  2. #12
    Join Date
    Nov 2007
    Posts
    1,253
    Tokens
    150

    Latest Awards:

    Default

    This is for making users charlie... am I been thick or something? At the moment it seems to be you...

    This is for making users, the admin variable is to determine if that user would have admin rights, it then stores the details in the database. $admin related to the admin column.


    www.fragme.co = a project.

  3. #13
    Join Date
    Mar 2008
    Posts
    5,108
    Tokens
    3,780

    Latest Awards:

    Default

    Quote Originally Posted by Hypertext View Post
    I hope your not basing administrator abilities on a post, fyi this could easily be spoofed.
    Quote Originally Posted by Hypertext View Post
    If it is, an $admin variable wouldn't be needed, as we'd already know it was in the admin control area.
    Can you really not interpret something as easy as that?

    It's a checkbox.. on/off? if checkbox is on, do you not get that?

    I mean.. you're a professional coder.. you should understand that?

    It's not posting permissions?! That would be stupid.


  4. #14
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default

    In which case, I'll change my point. Somebody could easily navigate to this page and send a spoofed $_POST array, thus adding themselves a user, which is dangerous, regardless of whether the page with the form is secure.
    How could this hapen to meeeeeeeeeeeeeee?lol.

  5. #15
    Join Date
    Nov 2007
    Posts
    1,253
    Tokens
    150

    Latest Awards:

    Default

    and the chances of that person knowing what the structure of the site is, and what the file name would be?


    www.fragme.co = a project.

  6. #16
    Join Date
    Mar 2008
    Posts
    5,108
    Tokens
    3,780

    Latest Awards:

    Default

    I'm pretty damn sure, that isn't all of his code.

    PHP Code:
    <?php
    include "config.php";

    $core->user->requireLogin();
    $core->user->requireAdmin();

    $action $_GET ["action"];

    switch(
    $action) {
        
    }
    ?>
    Couldn't spoof that.

    Plus he isn't asking for if it is secure or not, he's asking what's the matter with it.

  7. #17
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Dentafrice View Post
    I'm pretty damn sure, that isn't all of his code.

    PHP Code:
    <?php
    include "config.php";

    $core->user->requireLogin();
    $core->user->requireAdmin();

    $action $_GET ["action"];

    switch(
    $action) {
        
    }
    ?>
    Couldn't spoof that.

    Plus he isn't asking for if it is secure or not, he's asking what's the matter with it.
    Where did that code come from?

    And we're inferencing that. You could easily have made bad functions. of requireLogin() and requireAdmin().
    How could this hapen to meeeeeeeeeeeeeee?lol.

  8. #18
    Join Date
    Mar 2008
    Posts
    5,108
    Tokens
    3,780

    Latest Awards:

    Default

    It was an example..?

    of course I could have.. but I didn't.. :rolleyes:

  9. #19
    Join Date
    Nov 2007
    Posts
    1,253
    Tokens
    150

    Latest Awards:

    Default

    Twinkies.


    www.fragme.co = a project.

Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •