vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   security seems not a main priority in vb hacks (https://vborg.vbsupport.ru/showthread.php?t=73307)

aussiev8 12-26-2004 02:11 AM

security seems not a main priority in vb hacks
 
this is stupid, 2 hacks (major hacks as well with over 200 installs) i've found to be covered with holes and the simplest of hacking kiddies can exploit. This is a major issue in my opinion, and i think something needs to be done about it, or VB is going to turn into a phpnuke! and i'm sure you guys don't want that.

filburt1 12-26-2004 02:28 AM

Don't install anything that modifies vB code and you should be safe. It's extraordinarly difficult to generate a qualification system to verify a hack's security.

cinq 12-26-2004 02:38 AM

No code is 100% secure, not even a default VB installation.
But that is where feedback by users is required, for the developers to fix the holes and provide solutions and patches.

And good developers work hard not just to add new features, but make sure their applications ( in this case, hacks ) are as secure as possible.

Erwin 12-26-2004 03:00 AM

Add-ons on this site are written by 3rd parties who are not endorsed or supported by Jelsoft in any way - as such Jelsoft offers no guarantees and take no responsibility of any add-ons or "hacks" that are hosted here. Jelsoft does not offer support for modified or "hacked" forums. You install hacks at your own risk. If you find security holes, take it up with the author of the add-on.

TwinsX2Dad 12-26-2004 03:41 AM

Well said, Erwin.

In simpler wording:

Hack the code at your own risk.

It is pretty simple. Jelsoft creates the product and charges you for it. It is rather secure all by itself. Numerous people, either associated or unassociated with Jelsoft, but not working on Jelsoft's behalf, create mods (or toys, if you'd prefer) to change the code.

Buy a new car, toss on a bunch of aftermarket 'high-performance' mods and watch your warranty go down the tubes. Buy a new software package, tweak the snot out of it, and watch security holes appear.

The commercial companies, which produce this type of code, test it and test it some more. The hackers produce a plug-in or a modification, make sure it works, then put it out here for us to use. Unlike the commercial companies, the mods are beta tested by you and me - if there is a problem, there is no money-back guarantee, since you didn't pay money to begin with.

Hacked or not - you've invested under $200, which is peanuts.

AN-net 12-26-2004 03:58 AM

Quote:

Originally Posted by aussiev8
this is stupid, 2 hacks (major hacks as well with over 200 installs) i've found to be covered with holes and the simplest of hacking kiddies can exploit. This is a major issue in my opinion, and i think something needs to be done about it, or VB is going to turn into a phpnuke! and i'm sure you guys don't want that.

i believe instead of complaining about it you should inform the developer/coder of those security holes because this not the right way to go about it

aussiev8 12-26-2004 05:17 AM

yea i have done so. i think a tutorial written by one of the advanced coders about simple security holes like SQL injection should be included on here. Most of the scripts on here fail to utilise basic stripping techniques to combat such things as that. I'm not here to change the world, and i'm fully capable of creating my own advanced hacks/add ons, but think it's needed to keep VB respected. not like some of the other forum/cms systems out there!

Revan 12-26-2004 10:01 AM

If you could find and get permission to post such as guide, I as a dev of the RPG Hack would be most grateful.
Even though I don't know everything about SQL Injections, I know that they happen if a query is not secure enough, and since my RPG uses alot of queries, there's tons of room for such errors.
If you don't get permission to post, would you please link me to it?
TIA

//out

Dean C 12-26-2004 10:37 AM

SQL injection and XSS is one of the biggest problems developers face. However, I'm recently finding that if you design your applications correctly, it's here-nigh impossible for anyone to do so. I can't wait to see how they've done it in the next version of vB :)

Infopro 12-26-2004 11:15 AM

Quote:

Originally Posted by aussiev8
this is stupid, 2 hacks (major hacks as well with over 200 installs) i've found to be covered with holes and the simplest of hacking kiddies can exploit. This is a major issue in my opinion, and i think something needs to be done about it, or VB is going to turn into a phpnuke! and i'm sure you guys don't want that.

I'd like you to post the names of what hacks you know of that have holes please.


I respect Erwin, and I understand this post 100% ,
Quote:

Add-ons on this site are written by 3rd parties who are not endorsed or supported by Jelsoft in any way - as such Jelsoft offers no guarantees and take no responsibility of any add-ons or "hacks" that are hosted here. Jelsoft does not offer support for modified or "hacked" forums. You install hacks at your own risk. If you find security holes, take it up with the author of the add-on.
But some authors are long gone so taking it up with them can't be done. Holes should be fixed and we can't fix them if we all hide behind "install at your own risk"


All times are GMT. The time now is 08:08 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01020 seconds
  • Memory Usage 1,740KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete