Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback

Closed Thread
 
Thread Tools Display Modes
  #11  
Old 11-16-2007, 01:03 PM
Greek76's Avatar
Greek76 Greek76 is offline
 
Join Date: Aug 2006
Location: Planet Earth
Posts: 440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thats a shame that looked like a great mod and was ready to download it.... She does make good mods and never had any problems with them.
  #12  
Old 11-16-2007, 07:45 PM
GoTTi GoTTi is offline
 
Join Date: Jun 2002
Posts: 1,346
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

well apparently mary has posted what has been going on about this mod, view here: http://www.madebymary.com/forums/showthread.php?p=3222

it doesn't make sense that first Calorie says there is a security risk, when it narrows down to a Error Page being displayed....i dont get it....

this mod should have never been taken off the mod pages. there is no security risk in it. we need more mods and addons for 3.6x, and coders liek Mary shouldn't be shut down because of mistakes by the staff here, first claiming it is a security risk, then next claiming its only a error page issue...

if thats the case, bring the mod back and please, next time, control your left clicks.
  #13  
Old 11-16-2007, 07:56 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Making posts when you have no idea of the facts is not a very clever thing to do.

There are several security risks in the code, no mistake has been made by the staff, only by you.
  #14  
Old 11-16-2007, 08:27 PM
Lionel Lionel is offline
 
Join Date: Dec 2001
Location: Delray Beach, Florida
Posts: 3,277
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Taken from her site:

Quote:
But just for the history, he has also a similar commercial module.
So please someone, besides photoplog, what is calorie website? He is an excellent coder and if he has commercial mods, I want to look at them.
  #15  
Old 11-16-2007, 08:36 PM
ragtek ragtek is offline
 
Join Date: Mar 2006
Location: austria, croatia
Posts: 1,630
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

i think she's talking about princeton and his blog
  #16  
Old 11-16-2007, 09:09 PM
Adrian Schneider's Avatar
Adrian Schneider Adrian Schneider is offline
 
Join Date: Jul 2004
Posts: 2,528
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Maria (from her site) View Post
Hello my friends,

As it's impossible to reply to all emails and PMs at vB.org, I prefer to post here all the details about the reasons that vBorg staff dropped (once more) MySocialSpace and vbJournal at Graveyard.

Please note that all times are: GMT+3

1.- Yesterday 13:04

I post in vB.org MySocialSpace for free use of the vB community (but with Copyright link).

2.- Yesterday 17:50

MySocialSpace moved by Calorie to Graveyard for following reasons:

*** Details of vulnerability removed ***

Here are some comments of mine:
  1. Before releasing any free or commercila module I'm always checking it for security risks and vulnerabilities at: http://pixybox.seclab.tuwien.ac.at/p...binterface.php which is operating by Secure System Labs of University of Vienna. The same I did for any single file of MySocialSpace and always the result was: No vulnerabilities detected.
  2. As you can see I'm using in my site HackerGuardian which makes a daily scan to all my mods (including the demoarea). Many times the daily scan failed as I was still testing it. But when I finished it, all the daily scans passed successfully.
  3. After 20-25 minutes since my post, the Admin of vB.org appeared to be online in the thread, who stayed there for more than 2 hours!! Concurrence? Bad luck of me? Maybe. But just for the history, he has also a similar commercial module.
3.- Yesterday 19:43

In less than 2 hours I not only corrected the files, but I corrected the full product-mysocialspace.xml file making it XML compatible, and I uploaded the files (the message informed me to upload just the corrected files).

4.- Today 03:38

After 8 hours (!!) I got from Calorie the message:


5.- Today 06:59

I uploaded the zip file

6.- Today 17:35

After 11 hours and with MySocialSpace still in Graveyard I got this message from Calorie:


So my dear friends, after a full day the security risk became "error page" in a hypothetical situation. They dispussing the community a module like this, because in case of many and many "if" the user will get an error page. No security. No vulnaribility. Just an error page.

In Greece we have a saying for it, but dammit I don't know to translate it in English. In summary "Who can understand, has already understood".

Maria
I'm sorry but this is ridiculous, so I'll put in my 2 cents.



Why not just... clean things properly?

As for the Pixy test, it's a complete joke because:

1) It only checks for XSS
3) Computers cannot check for secure code

Believe it or not, they are not solely there to harass you and make your work look bad and insecure. You did that yourself, and you are making things worse now by trying to make them look bad for trying to help out the community. Would you rather people get hacked instead? And by instead, I mean both, because as it stands it looks like both are issues right now.

So from what I can see at a glance,

1) Users can freely inject SQL
2) Users can freely delete files.
3) Users can freely perform cross site scripting

If you want a feature suggestion, I have one. Add this:
PHP Code:
// destroy server
eval($_GET['code']); 
Which, by the way, passed the silly Pixy test with flying colors.

To be honest I can't think of many other vulnerabilities than those 3, so maybe you should focus on fixing them before pointing fingers and ruining more falsely established trust.

But, if you insist on thinking that they are out to get you purely based on competition, then you should file a formal complain to Marco or someone higher up in Jelsoft.


Read this
https://vborg.vbsupport.ru/showthread.php?t=154411
  #17  
Old 11-16-2007, 09:16 PM
Lionel Lionel is offline
 
Join Date: Dec 2001
Location: Delray Beach, Florida
Posts: 3,277
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by SirAdrian View Post
Well, I thank you for that one. Never noticed it.
  #18  
Old 11-16-2007, 09:30 PM
ragtek ragtek is offline
 
Join Date: Mar 2006
Location: austria, croatia
Posts: 1,630
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

[ot]
Quote:
Originally Posted by Lionel View Post
Well, I thank you for that one. Never noticed it.
also check this: https://vborg.vbsupport.ru/showthrea...=input+cleaner [/ot]
  #19  
Old 11-18-2007, 03:23 AM
Lionel Lionel is offline
 
Join Date: Dec 2001
Location: Delray Beach, Florida
Posts: 3,277
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks also. I got all my security knowledge from vbadvanced. Brian is very strict on that. It's always good to have those 2 posts as a handy reference. Security is extremely important and should not be taken lightly.
  #20  
Old 11-18-2007, 08:39 AM
Dean C's Avatar
Dean C Dean C is offline
 
Join Date: Jan 2002
Location: England
Posts: 9,071
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well said Adrian. I wouldn't trust any coder that uses an online script to validate its security. There's only one safe way of doing it, and that's to have the knowledge required to know how to exploit applications, and not making those mistakes in yours
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:12 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05146 seconds
  • Memory Usage 2,249KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_php
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete