Waraxe IT Security Portal
Login or Register
April 20, 2025
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 255
Members: 0
Total: 255
Full disclosure
83 vulnerabilities in Vasion Print / PrinterLogic
[CVE-2025-32102, CVE-2025-32103] SSRF and Directory Traversal in CrushFTP 10.7.1 and 11.1.0 (as well as legacy 9.x)
Re: APPLE-SA-03-11-2025-2 iOS 18.3.2 and iPadOS 18.3.2
[KIS-2025-01] UNA CMS <= 14.0.0-RC4 (BxBaseMenuSetAclLevel.ph p) PHP Object Injection Vulnerability
OXAS-ADV-2025-0001: OX App Suite Security Advisory
APPLE-SA-04-01-2025-1 watchOS 11.4
APPLE-SA-03-31-2025-11 visionOS 2.4
APPLE-SA-03-31-2025-10 tvOS 18.4
APPLE-SA-03-31-2025-9 macOS Ventura 13.7.5
APPLE-SA-03-31-2025-8 macOS Sonoma 14.7.5
APPLE-SA-03-31-2025-7 macOS Sequoia 15.4
APPLE-SA-03-31-2025-6 iOS 15.8.4 and iPadOS 15.8.4
APPLE-SA-03-31-2025-5 iOS 16.7.11 and iPadOS 16.7.11
APPLE-SA-03-31-2025-4 iPadOS 17.7.6
APPLE-SA-03-31-2025-3 iOS 18.4 and iPadOS 18.4
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index
Search found 29 matches
Can you help me? my forum has been hacked
PostForum:How to fix Posted: Fri Mar 04, 2005 6:20 pm Subject: A simple guide to secure a forum
Zeelock
Replies: 10
Views: 24252




- First use .htaccess for protection admin directory and admin files

- Second use only one admin

- Disable System() and any other dangerous function (if not used)

- Third For forums only use ...
Postnuke all versions + pnphpbb <=1.2 sql injection
PostForum:PostNuke Posted: Fri Mar 04, 2005 12:20 pm Subject: Postnuke all versions + pnphpbb <=1.2 sql injection
Zeelock
Replies: 5
Views: 16973




It's a bug in old Phpbb. Of course if you use old phpbb versions...
Howto Find bugs?
PostForum:Newbies corner Posted: Fri Mar 04, 2005 11:43 am Subject: Howto Find bugs?
Zeelock
Replies: 4
Views: 10654




Really good is to use a debugger.

Using Zend is amazing what you can find...
phpbb v. 2.0.12 and earlier authendication bypass
PostForum:PhpBB Posted: Mon Feb 28, 2005 1:53 pm Subject: phpbb v. 2.0.12 and earlier authendication bypass
Zeelock
Replies: 15
Views: 41750




If you want I'll censor the info as well
Debugging with ZEND
PostForum:Php Posted: Mon Feb 28, 2005 1:52 pm Subject: Debugging with ZEND
Zeelock
Replies: 0
Views: 7014




I'm using since a while Zend STudio.

Yesterday I tryed for the first time version 4.0 and I was impressed.

Auditing and debugging is far away easier!
phpbb v. 2.0.12 and earlier authendication bypass
PostForum:PhpBB Posted: Mon Feb 28, 2005 11:03 am Subject: phpbb v. 2.0.12 and earlier authendication bypass
Zeelock
Replies: 15
Views: 41750




I think that Janek censored the message, because it's really harmful at the moment
MercuryBoard v1.1.2
PostForum:All other software Posted: Mon Feb 28, 2005 9:14 am Subject: MercuryBoard v1.1.2
Zeelock
Replies: 2
Views: 9379




For the code injection you need to have Magic Quotes disabled. If you have the protection On, you should be safe

To fix the sql Injection Change:

if (!$mercury->perms->is_guest) &# ...
phpbb v. 2.0.12 and earlier authendication bypass
PostForum:PhpBB Posted: Mon Feb 28, 2005 8:40 am Subject: For comparing Strings use ===
Zeelock
Replies: 15
Views: 41750




Heintz Great Job.

Even if it's a common trick and well documented I didn't notice it yet ( Shocked ).

This error is very common in converting perl scripts into php.

For more info:

http://www.ph ...
MercuryBoard v1.1.2
PostForum:All other software Posted: Mon Feb 28, 2005 8:35 am Subject: Blind SQL-Injection
Zeelock
Replies: 2
Views: 9379




I already have made a template-tutorial for blind injection in MercuryBoard.

Anyway this is not a Select, it's a replace.

You can change the active item:

You have an error in your SQL syntax. ...
XSS remote control
PostForum:Cross-site scripting aka XSS Posted: Fri Feb 25, 2005 8:46 am Subject: XSS remote control
Zeelock
Replies: 4
Views: 12886




The guy that developed it is Anton Rager.

To have more info about there is his paper about:
http://xss-proxy.sourceforge.net/Advanced_XSS_Control.txt

I found it very interesting, even if the gu ...
vBulletin 3.0.6 and prior versions Exec commands in server
PostForum:Shell commands injection Posted: Thu Feb 24, 2005 10:43 am Subject: vBulletin 3.0.6 and prior versions Exec commands in server
Zeelock
Replies: 12
Views: 27806




Original Link: http://www.milw0rm.com/id.php?id=832

Made by Pokleyzz
Vulns in Phpbb 2.0.11
PostForum:PhpBB Posted: Wed Feb 23, 2005 8:51 am Subject: Unink ()
Zeelock
Replies: 10
Views: 17360




Just for deleting files,

Quote from Idefense:

Remote exploitation of an input validation vulnerability in the phpBB
Group's phpBB2 bulletin board system allows attackers to unlink (delete)
ar ...
Vulns in Phpbb 2.0.11
PostForum:PhpBB Posted: Mon Feb 21, 2005 8:53 am Subject: These Exploits
Zeelock
Replies: 10
Views: 17360




This kind of stuff is good because it gives information about table prefixes.

In the errors you can acknowlegdge the full name of the table.

There is another issue here:

http://www.site.com/ ...
Vulns in Phpbb 2.0.11
PostForum:PhpBB Posted: Fri Feb 18, 2005 6:20 pm Subject: Magic Quotes
Zeelock
Replies: 10
Views: 17360




it doesn't seem to be exploitable :-]

Yep It deals with the magic quotes and the backslash.


From the manual:

When magic_quotes are on, all ' (single-quote), " (double quote), (backslash) an ...
Phishing with Unicode Tricks
PostForum:All other security holes Posted: Fri Feb 18, 2005 11:50 am Subject: Phishing with Unicode Tricks
Zeelock
Replies: 0
Views: 7768




http://www.schneier.com/blog/archives/2005/02/unicode_url_hac_1.html
Page 1 of 2 Goto page 1, 2Next
All times are GMT


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.040 Seconds