Page 1 of 5 12345 LastLast
Results 1 to 10 of 45
  1. #1
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default Cutenews - Don't use it

    Well I have noticed theres alot of people questioning about cutenews. I advise you NOT to use it, as there is now a script where you enter the username you wish to display the password (md5 hash). So if any staff members have a dictionary word as there password, there likely to get hacked.

    Dont belive me?
    Give me a link to your cutenews directory, and set up an account with a assword as a dictionary word (Or in the reverse md5 hash database).

  2. #2
    Join Date
    Dec 2006
    Location
    London
    Posts
    3,536
    Tokens
    170

    Latest Awards:

    Default

    Sounds interesting. MD5 thingy rings a bell from MySQL databases and phpAdmin. Anyways, ye.
    2005: JOINED ; Radio DJ

    2006: Radio DJ ; Senior DJ

    2007: HxTV Flash Artist ; Productions Staff ; HxHD Staff ; Head DJ ; Events Organiser ; Productions Staff ; Competitions Staff ; Assistant Radio Manager

    2008: Senior Competitions Staff ; Forum Moderator ; HxHD Staff ; Competitions Manager ; Graphics Designer

    2009: LEFT ; Guest DJ

  3. #3
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    Quote Originally Posted by H0BJ0B View Post
    Sounds interesting. MD5 thingy rings a bell from MySQL databases and phpAdmin. Anyways, ye.
    Because cutenews is a text based database, you can easily extract infomation on the users as easy as you can display news from the news.txt

  4. #4
    Join Date
    Nov 2006
    Location
    Bolton
    Posts
    3,564
    Tokens
    1,804

    Latest Awards:

    Default

    Or just change your password to a better one

  5. #5
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    Quote Originally Posted by Nevernoob View Post
    Or just change your password to a better one
    Its the staff though

  6. #6
    Join Date
    Jun 2007
    Location
    Kilmarnock
    Posts
    3,227
    Tokens
    50

    Latest Awards:

    Default

    Who cares lol? It can easily be hidden in a directory unknown.
    CPU i5 3570 @ 4.2 GHz | Mobo GigaByte Z77D3H | RAM 8GB | GPU AMD Radeon 6870 | OS Win 8 64-bit | HD 1TB HD and 128GB SSD | Wheel Logitech G27

  7. #7
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    Quote Originally Posted by G-BOAH View Post
    Who cares lol? It can easily be hidden in a directory unknown.
    The attack uses $_COOKIE

  8. #8
    Join Date
    Jul 2006
    Location
    Leeds
    Posts
    17,006
    Tokens
    26,134
    Habbo
    e5

    Latest Awards:

    Default

    What if your pw was antiestablishmentarianism? :8

  9. #9
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    Quote Originally Posted by Elliott-1 View Post
    What if your pw was antiestablishmentarianism? :8
    Then the result would be 6547cd22b0e4de8a2d64dc6341cfd73c

  10. #10
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    But you wouldn't be able to get the password. That's what elliot means.

Page 1 of 5 12345 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •