Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 47
  1. #21
    Join Date
    Oct 2007
    Location
    Luton, England
    Posts
    1,548
    Tokens
    388
    Habbo
    DeejayMachoo

    Latest Awards:

    Default

    Quote Originally Posted by Jamieb View Post
    WOO there isnt a nav.php file:S

    edit got it./.

    whats this

    PHP Code:
                                                    [IMG]http://thebobbas.net/staffpanel/images/nav_top.png[/IMG]                                           
    Warning:  include(inc/nav.php) [function.include]: failed to open streamNo such file or directory in /home/thebobba/public_html/staffpanel/login.php on line 89

    Warning
    :  include(inc/nav.php) [function.include]: failed to open streamNo such file or directory in /home/thebobba/public_html/staffpanel/login.php on line 89

    Warning
    :  include() [function.include]: Failed opening 'inc/nav.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php'in /home/thebobba/public_html/staffpanel/login.php on line 89 
    Itz in the zip


  2. #22
    Join Date
    Oct 2006
    Location
    BUXTON
    Posts
    2,191
    Tokens
    0

    Latest Awards:

    Default

    Thanks.. Is there a way to add more things to profle system?

  3. #23
    Join Date
    Oct 2007
    Location
    Luton, England
    Posts
    1,548
    Tokens
    388
    Habbo
    DeejayMachoo

    Latest Awards:

    Default

    Ill add custom profile fields in the next version.


  4. #24
    Join Date
    Apr 2007
    Location
    england
    Posts
    536
    Tokens
    0

    Default

    Thanks for helping me out Matt.

    Very nice panel.


    Selling DJ/Habbo layout, more info here.


  5. #25
    Join Date
    Oct 2007
    Location
    Luton, England
    Posts
    1,548
    Tokens
    388
    Habbo
    DeejayMachoo

    Latest Awards:

    Default

    Second DEMO
    http://habboboards.com/HSP/
    User: demo
    Pass: demo


  6. #26
    Join Date
    Sep 2006
    Location
    Hobart, Australia
    Posts
    593
    Tokens
    0

    Default

    Good... But as Invent said, many many many security flaws.

    Take this for instance:



    That worked. Now, that code was fairly harmless, but if Javascript is working, it can easily be used to send the user to a site that logs their cookie information, or to a porn site etc.

    Whenever you're going to be displaying something like that, escape it with htmlentities():

    PHP Code:

    $var 
    htmlentities($news['newscontent']); 
    Will show HTML tags as the actual characters (won't convert them to HTML).

  7. #27
    Join Date
    Oct 2007
    Location
    Luton, England
    Posts
    1,548
    Tokens
    388
    Habbo
    DeejayMachoo

    Latest Awards:

    Default

    Thanks ill work on adding to the next ver benzor

    also +rep to all constructive critasisum (w/e its spelt)


  8. #28
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    This is highly insecure. I do not recommend you use it until the security issues are fixed. Input from POST and GET variables are being put directly into SQL queries. None of the input is cleaned for XSS or any other attack using javascript.

  9. #29
    Join Date
    Sep 2006
    Location
    Hobart, Australia
    Posts
    593
    Tokens
    0

    Default

    Quote Originally Posted by Tomm View Post
    This is highly insecure. I do not recommend you use it until the security issues are fixed. Input from POST and GET variables are being put directly into SQL queries. None of the input is cleaned for XSS or any other attack using javascript.
    Unfortunately, Tom is right. And may I add, this is the same with most, DJ panels for release now. Developers should be making sure they are sanitizing both POST and GET inputs, escaping HTML when displaying data etc.

  10. #30
    Join Date
    Oct 2007
    Location
    Luton, England
    Posts
    1,548
    Tokens
    388
    Habbo
    DeejayMachoo

    Latest Awards:

    Default

    Quote Originally Posted by benzoenator View Post
    Unfortunately, Tom is right. And may I add, this is the same with most, DJ panels for release now. Developers should be making sure they are sanitizing both POST and GET inputs, escaping HTML when displaying data etc.
    Ok thanks for the comments and i will work with H! get try to get a Security fix out tonight.


Page 3 of 5 FirstFirst 12345 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •