Username:
Password:
Remember me:
Register

Back to forum: Error / Bug Reports


Search forums via Google


1 Users appreciate this thread.

Admin hole in security
Started by Leviathan
(2014-09-21 08:35:28)
Leviathan (2014-09-21 08:35:28)
So I was running some site diagnostics, and noticed that www.3dsplaza.com/members is open to everybody. As some of you may know, this is an Administration page, and is extremely vulnerable to SQL injection. As well as Ddos. I suggest restricting it to administrators only.


Thank you.
I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
carlos11 (2014-09-21 19:01:23)
This is like seeing Lady Plaza naked.
Language is a tool for efficient communication. The internet is a tool for fast communication. Do not defy both intents by posting incoherent writing.
Leviathan (2014-09-21 21:47:23)
I'm not sure if that is an insult, or an exclamation of astonishment.
I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
little5 (2014-09-22 10:14:44)
So many people have done MySQL injections and DoS'd the site, it's not we've funny.
Leviathan (2014-09-22 17:29:59)
But this page makes it easy to do so. I did an SQL injection for diagnostic purposes, and it found a keyword, and only had trouble detecting the database. Somebody with a fast computer or extreme patience could get in through /members.


EDIT: MySQL is a database, not an injection. and Dos is a coding language. You mean DDos.

This post has been edited one or more times, the last time was:
2014-09-23 00:32:31

I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
SomeLuigi (2014-09-26 15:23:48)
/members/ is a directory.

Which file allows MySQL injection? (Please send via PM as this is a matter of security).
SomeLuigi is changing in 2015.
Leviathan (2014-09-27 02:17:18)
It's not "MySQL" injection. MySQL is a database type, such as oracle, that allows for SQL injection. Anyways I sent the PM.
I'm an open book, there are few questions I won't answer honestly, no matter how embarrassing.
gliycheyfox (2016-02-18 23:17:15)
....You just made SQL injection easier for people by telling everyone it's MySQL :I
AntiChrist (2016-02-21 16:58:11)
Old thread. I have to close this because it was bumped from a long time ago
 

This topic is closed, so you can not post a comment.

This topic's ID: 76403

Back to forum: Error / Bug Reports




Total registered users: 8321
New registered users today: 7
Newest registered user: ElegantVulpes

©  Copyright 2026 3DSPlaza. All Rights Reserved