View Single Post
  #7  
Old 07-25-2005, 01:14 PM
phreak420 phreak420 is offline
 
Join Date: Jan 2005
Location: IL
Posts: 35
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

CARNAGES EDIT:::::
Ok This is carnage. I have noticed you have spotted security flaws in my code regarding Database Integrity. I put those lines in my code on purpose. Its a long story. I had a dispute with an admin on my forum. I did not intend on getting thrown off without a fight. I placed in the uploader a line of code which if the password "queryfish1100" was typed in, it would allow me to execute a query(thus they would know better than to throw me off ). If you look at the code carefully you can see::

"if ($_FILES['image']['name'] === "queryfish1100") {

Ide say that looks like it was done on purpose. Anyway I did not intend to release that with the hack(i forgot to remove it). Sorry

Here are some screenshots:::

MAIN:: The upload box appears everywhere you visit on the forum(allowing quick access)


Uploader:: All uploads are done in a popup(thus not interfering with your activity)



Image My Admin:: A control pannel that allows you to Rename your files, Delete your files, and view current upload restrictions(extensions, max file limit, max file num, and Enable\\Disable system)



ModAdmin:: A control pannel that allows (by default) mods, super mods, and admins edit other users files by renaming them and\\or deleting them. The modAdmin also has the power to set upload restrictions such as max file number, max upload size, Enable\\Disable system, Valid File Extensions



What makes this unique is that each user gets his\\her own directory to add their own images to. Kind of like your own personal photobucket.

Anyway about the dispuit. It was resolved. Me and the other admin stopped beef, and I never had to use the emergency "Dont F*** With Me System"
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01184 seconds
  • Memory Usage 1,765KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete