CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 951
Comments: 28
block bottom
spacer spacer

Site vulnrable ??

 
Post new topic   Reply to topic       All -> FavForums -> General Site [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
stack

Cadet
Cadet


Joined: Dec 12, 2002
Posts: 1
Location: USA

PostPosted: Thu Dec 12, 2002 6:59 am    Post subject: Site vulnrable ??
Reply with quote

It seems to me that your site is vulnrable. If you allow me, I can test it and give u the suggestions.

-Stack

Back to top
View users profile Send private message
cj

Site Moderator
Premium Member

Joined: Mar 06, 2002
Posts: 647
Location: USA
Moderators Premium

PostPosted: Thu Dec 12, 2002 7:25 am    Post subject:
Reply with quote

Hello stack and welcome to CCSP. Wishing that you enjoy your stay.

If there are any vulnerablities to your finding please submit your results with full details to the site Admin. His name is Paul and he shall contact you a.s.a.p.


Admin Contact:
Paul Laudanski
paul{-AT-}computercops.biz

Thank you,

-cj.- Very Happy
______

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
stack

Guest
IP: 210.214.*.*






PostPosted: Thu Dec 12, 2002 7:32 am    Post subject:
Reply with quote

Ok...i will e-mail him..thx..

-Stack

Back to top
cj

Site Moderator
Premium Member

Joined: Mar 06, 2002
Posts: 647
Location: USA
Moderators Premium

PostPosted: Thu Dec 12, 2002 7:58 am    Post subject:
Reply with quote

Glad to have you on board and active on site!

Thanks for posting!

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Thu Dec 12, 2002 11:15 am    Post subject:
Reply with quote

Yes replied to the email. My question is, what leads you to suspect there is a vulnerability?


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
stack

Guest
IP: 210.214.*.*






PostPosted: Fri Dec 13, 2002 12:17 pm    Post subject: :)
Reply with quote

Glad to see such a wonderful and practical admin !!

-Stack it..

<b onMouseOver="alert(document.location);">Here is a poosible exploit !! Move ur mouse here and you will see something. A malicious user can possibly exploit this. Disable HTML codes!!</b>

Back to top
stack

Guest
IP: 210.214.*.*






PostPosted: Fri Dec 13, 2002 12:19 pm    Post subject:
Reply with quote

It's possible to write such a code to steal cookie of another users using this html-code exploit.

-Stack..

Back to top
stack

Guest
IP: 210.214.*.*






PostPosted: Fri Dec 13, 2002 12:22 pm    Post subject: also..
Reply with quote

Also..why don't u update to phpBB 2.0.3 ? There may be other bugs in older version.

-Stack..

Back to top
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Dec 13, 2002 12:41 pm    Post subject:
Reply with quote

Hmm, I thought I disabled HTML completely. Well now it is. I've been too caught up in my daily work schedule to upgrade the site so I've been patching and locking things down in the meantime.

I am expecting some time in January to begin upgrading the software.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Site All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer