[HELP]Better Security for dk server

03/08/2010 23:21 crankdup#1
hey guys this is my first post asking for help, and yes ive used the search alot. your not gonna see this alot from me because im trying to learn like the old dev's...but wanna try and avoid SQL injects and get an adminpanel working..for ipbanning. ive tried OSDS but ive been sql injected through that before thats why im asking for just alittle bit of help this time. if anyone has any tips for me to help make a better secure server then please by all means help me out just alittle bit.

props to your work janvier123 but i dont wanna get sql injected again. if you have a fix to help me with it ill use it definately.
03/09/2010 06:00 pieter#2
[Only registered and activated users can see links. Click Here To Register...]

[Only registered and activated users can see links. Click Here To Register...]

[Only registered and activated users can see links. Click Here To Register...]

basicly

- dont use SA for webscripts
- dont use xampp
- dont leave test php scripts anywhere publicly available on your server
- anti-sql inject any variable that gets used in a query
- for best result run a separate server for web
- backup or replicate data

oh and also try these addons:

[Only registered and activated users can see links. Click Here To Register...]

[Only registered and activated users can see links. Click Here To Register...]

[Only registered and activated users can see links. Click Here To Register...]

for any questions about those topics please reply on dku not here
03/09/2010 07:28 Zombe#3
Reported pieter for advertising another forum ^^
Sorry bro, rules are rules :D
03/09/2010 07:44 pieter#4
uh dku links back to e-pvp, thought that wasnt an issue then?
03/09/2010 09:21 janvier123#5
Quote:
Originally Posted by Zombe View Post
Reported pieter for advertising another forum ^^
Sorry bro, rules are rules :D
Pieter is right, i had this discussion with trane.
Dkunderground it NOT a p-server, so its allowed, it if dont abuse it,
but i cant take responsibility for others
03/09/2010 10:40 gedimazs#6
Quote:
Originally Posted by crankdup View Post
hey guys this is my first post asking for help, and yes ive used the search alot. your not gonna see this alot from me because im trying to learn like the old dev's...but wanna try and avoid SQL injects and get an adminpanel working..for ipbanning. ive tried OSDS but ive been sql injected through that before thats why im asking for just alittle bit of help this time. if anyone has any tips for me to help make a better secure server then please by all means help me out just alittle bit.

props to your work janvier123 but i dont wanna get sql injected again. if you have a fix to help me with it ill use it definately.
Just wait for OsDs v2
03/09/2010 10:48 pieter#7
there are more risks then just OSDS lol.

especially for the ppl using 1 click servers

xampp = litterally asking to e hacked for example
03/09/2010 10:49 pa1n#8
Thanks for the tools =)
03/09/2010 13:07 Zombe#9
Wait, I just read the rules again, it says
Quote:
Originally Posted by S.A.L.O.M.O.N
Advertising your own forum hosted at a free-forum provider is not allowed.
Wait, so does that mean that if its like "blablabla.freeforumhostingorsmth.com" then its forbidden, but if its like "blablabla.com/forum" then its allowed?
Just asking, sorry for off-topic.
03/09/2010 13:14 bottomy#10
Quote:
Originally Posted by Zombe View Post
Wait, I just read the rules again, it says


Wait, so does that mean that if its like "blablabla.freeforumhostingorsmth.com" then its forbidden, but if its like "blablabla.com/forum" then its allowed?
Just asking, sorry for off-topic.

Well i know you aren't allowed to post links to other game hacking forums, not sure if it's the same for other forums.


EDIT: I'm pretty sure you can post like official 2moons forums links, so my guess is you're allowed to post links to forums if it's for helping the community. But not if it's going to 'steal' members (a competing forum).
03/09/2010 13:14 pieter#11
(offtopic)
RE to Zombe:

It's clear to me:

- DKU is NOT hosted on e freeforumhost
- DKU links back to epvp
- DKU is not a private server
- Janvier and trane allready had a discussion about it and it was allowed

(sorry for offtopic, just wanted to clear things up)
03/10/2010 01:44 crankdup#12
thx pieter, janvier, and zombe...but your right about the whole osds not being that big of an issue...so what program should i use instead of xampp?
03/10/2010 06:35 gedimazs#13
Quote:
Originally Posted by crankdup View Post
thx pieter, janvier, and zombe...but your right about the whole osds not being that big of an issue...so what program should i use instead of xampp?
Try to install apache only
03/10/2010 07:56 pieter#14
apache, php, and if needed enable mod_rewrite and other modules in apache

and take time to configure apache's server.conf and php's php.ini

xampp is made for development purposes not to run a public website!