Security Issues in most public Private Servers

12/11/2013 23:44 »jD«#16
Quote:
Originally Posted by cryz35 View Post
Nice thread, are you going to add aurora-azure security holes? Just wonder.

I know some not important ones, may you see [Only registered and activated users can see links. Click Here To Register...] when you have free time?
If you want I can give you some information to help you protect it. There is still some exploits in your login form.

-jD
12/11/2013 23:55 cryz35#17
Quote:
Originally Posted by linkpad View Post
Your website is vulnerable, I can dump every database.



I can even access account by decrypting md5 hash...
lol website part simply sucks, I didn't pay much attention :p Can you tell me the files?

Quote:
Originally Posted by »jD« View Post
If you want I can give you some information to help you protect it. There is still some exploits in your login form.

-jD
I'll be glad to know the problems, thank you..
12/12/2013 00:45 »jD«#18
Quote:
Originally Posted by linkpad View Post
Have you find any exploits on [Only registered and activated users can see links. Click Here To Register...] ? Just for let me know
I'm currently running an Audit. First things first, you have a bunch of open ports running some exploitable version of software. Just lettin you know.

Also, there seems to be some time-based stuff in the signup form.

-jD
12/12/2013 13:53 linkpad#19
Are you sure I have a bunch of open ports ? I did a nmap, and there's only 8 ports opens.
Also I don't really understand what you mean by "time-based" stuff in the signup form could you explain a little ?
12/12/2013 20:36 manulaiko#20
Thanks for the report I really didn't notice it
12/12/2013 21:41 Sήøwy#21
What is SQL Injection?

SQL Injection is a web based attack used by hackers to steal sensitive information from organizations through web applications. It is one of the most common application layer attacks used today. This attack takes advantage of improper coding of web applications, which allows hackers to exploit the vulnerability by injecting SQL commands into the prior web application.

The underlying fact that allows for SQL Injection is that the fields available for user input in the web application allow SQL statements to pass through and interact with or query the database directly.

For example, let us consider a web application that implements a form-based login mechanism to store the user credentials and performs a simple SQL query to validate each login attempt. Here is a typical example:

select * from users where username=’admin’ and password=’admin123′;

If the attacker knows the username of the application administrator is admin, he can login as admin without supplying any password.

admin’–

The query in the back-end looks like:

Select * from users where username=’admin’–’ and password=’xxx’;

Note the comment sequence (–) causes the followed query to be ignored, so query executed is equivalent to:

Select * from users where username=’admin’;

So password check is bypassed.
For more: [Only registered and activated users can see links. Click Here To Register...]
01/21/2014 17:47 Requi#22
I thought about adding to my sticky thread just in case somebody isn't as good as some coders here to know this.

btw:
Could you check my page again? :p
02/11/2014 10:22 »jD«#23
Just a heads up, still a bunch of exploits out there ;)

-jD
12/17/2014 15:18 Kadhras_TR#24
Good job
12/17/2014 21:30 mr.x3#25
all those private servers out there are useless,

if you want to make a real safe, good and stable, you can do it alone but you need tobe a master designer, coder, and a genius :P, if you work in a team with talented people, like a designer, a coder, a cybersecurity expert etc.. then you can create a game just like do and release it, without being scared for bigpoint, blackgalaxy is kind of a simple version, of what i mean but it was hard to make,

so dont try to make a private server, if you dont know coding, hackers can get it down by studying the code and figuring out the weak spots. it''s pretty simple for a real talented coder.

and jd, what happened to ur private server ?
12/19/2014 01:05 »jD«#26
My Private Server is making a comeback. I'm working on getting everything back online now!

*cough* [Only registered and activated users can see links. Click Here To Register...] *cough*

-jD
12/19/2014 01:20 manulaiko3.0#27
lol -jD is alive!
12/19/2014 01:42 mr.x3#28
server looks nice!


can't wait for it to come out
12/19/2014 03:04 Nommo#29
Well, new looks really nice! Waiting for server to come online ;)

If you need help in any ways feel free to PM me (translations, testing etc.).

Maybe you still remember me -Jd :P

Regards,
Nommo.
12/19/2014 10:53 UND3RW0RLD#30
Quote:
Originally Posted by »jD« View Post
My Private Server is making a comeback. I'm working on getting everything back online now!

*cough* [Only registered and activated users can see links. Click Here To Register...] *cough*

-jD
I could spend some moduls to solve some comings soons. ;)