Activity Stream
48,167 MEMBERS
6716 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 3 of 7 FirstFirst 12345 ... LastLast
Results 21 to 30 of 70
  1.     
    #21
    Member
    Website's:
    zomgbbqpizza.com evilddl.com scenemarket.org
    Anybody not using php 5 is crazy.. infact anyone still using php4 is very crazy...

    But yes i klnow you have your own ddl script, i was more refering to the pthers but a bit of advice here and there from somebody with experience never hurts.

    I personally intend to use this for a while and make a few mods, so i am all up for helping in anyway i can as it will benefit me too. I have already made a couple of small mods, one seriously improves performace. Just need to find a skinner and i am set.

  2.     
    #22
    Banned
    Website's:
    Dev-Security.net
    Well darn

    Ok @ deviance on some servers i have it compiled with php4 + php5 and enhanced the security on both of them

    The reason as to why i think it is blocking it is because of mycrypt i dont fully understand it yet but by the looks of it it looks like its checking bytes by 29 and 36 or 30 if you run a script and it doesnt compare to those it does not execute

    by using ../../../../ it will block it but if we encode you can try and use

    %20/% followed by the /etc/passwd


    Thats just a theory if we take a look at how the transversial is even executing we can look here

    If we tried to inject this code onto ?wwwRoot it would not work why? beacuse wwwRoot is basically a addon to the variables to config.php killthread.php and basedir so if executing a load o f include functions of config / killthread was not found

    But in the variable baseDir it connects all the variables together making it the big guy

    Code: 
    $baseDir = substr($wwwRoot, 0, ##BASEDIR##);
        require($baseDir . 'funcs.inc');
        require($baseDir . 'config.php');

    Any other ideas can be great i will be testing this script for javascript injection and other stuff later on today

  3.   Sponsored Links

  4.     
    #23
    Member
    Website's:
    ddlcms.com xsaimex.com warezgod.com
    Keep in mind, you are all testing the first release of this script, which was appropriately called a "beta" release.

    Also, my reply states, and I quote again

    Code: 
    "This exploit for misconfigured servers 
    has been removed in the latest release of this script."
    so I admitted that the script indeed had an exploit for misconfigured servers, but was already addressed prior to this post, and fixed. Why then, JmZ, do you keep harping about it? Go away man, seriously.

    Quote Originally Posted by JmZ View Post
    I love it when I get quoted so many times.
    I love quoting you JmZ because you only make yourself out to look like a damn fool with each reply, and, it re-iterates your lack of respect, lack of dignity, and especially your shameless arrogance, as pointed out by this last quote. I'm sure you will reply again, this time with love and respect and genuine heart-felt assistance (yeah right)... hey JmZ, do me a favour again and hover your mouse cursor over this smiley

  5.     
    #24
    Respected Developer
    Website's:
    PlatinumW.org NexusDDL.com HD-United.org CheckLinks.org FLVD.org
    Good work on fixing exploit

  6.     
    #25
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    I'm simply pointing out facts, it is you who tries to turn it personal (and doesn't succeed, ever).

    Maybe one day you should listen to my posts and notice that it really does contain quite a few exploits. If you understand that and recognise it as a fact, you can have your coder(s) check the code.

  7.     
    #26
    Member
    Website's:
    ddlcms.com xsaimex.com warezgod.com
    Quote Originally Posted by JmZ View Post
    I'm simply pointing out facts, it is you who tries to turn it personal (and doesn't succeed, ever).

    Maybe one day you should listen to my posts and notice that it really does contain quite a few exploits. If you understand that and recognise it as a fact, you can have your coder(s) check the code.
    Here, let me repeat myself the third time, and perhaps I should use the big, colour coded letters, because it seems you keep missing it.

    Code: 
    Keep in mind, you are all testing the first release of 
    this script, which was appropriately called a "beta" 
    release.
     
    Also, my reply states, and I quote again
     
    Code:
    "This exploit for misconfigured servers has been removed 
    in the latest release of this script."
    so I admitted that the script indeed had an exploit for 
    misconfigured servers, but was already addressed prior to 
    this post, and fixed. Why then, JmZ, do you keep harping 
    about it? Go away man, seriously.
    Hey JmZ, here's an idea, bring it up again, how the first release has exploits and harp your ass off about it all over again, I'm sure you planned on it as usual. Hey Jmz do me a favour again and hover your mouse cursor over this smiley

  8.     
    #27
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    Yes I see, it's a beta. But is it not true that the reason in having a beta is to fix bugs and vulnerabilities? Yet you seem to completely ignore my "tips" to you.

  9.     
    #28
    Member
    Website's:
    InvestDude.com
    both of you should partner up
    InvestDude.com Learn to make money by investing in hyips (high yield investment programs), affiliate marketing and tons of other method ;)

  10.     
    #29
    (╯?□?)╯︵ ┻━┻
    Website's:
    Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.com
    Well he's not the coder so that wouldn't be very useful lol.

    Anyway, I made my point, he can take the hint or not. All im saying is the script contains exploits. Yes it's a beta but the point in that is to learn where the vulns are, so go do that.

  11.     
    #30
    Member
    Website's:
    ddlcms.com xsaimex.com warezgod.com
    Quote Originally Posted by JmZ View Post
    Well he's not the coder so that wouldn't be very useful lol.

    Anyway, I made my point, he can take the hint or not. All im saying is the script contains exploits. Yes it's a beta but the point in that is to learn where the vulns are, so go do that.
    Quote Originally Posted by JmZ View Post
    Yes I see, it's a beta. But is it not true that the reason in having a beta is to fix bugs and vulnerabilities? Yet you seem to completely ignore my "tips" to you.
    God damn. How many times are you going to keep bringing up the same stupid crap. What an idiot. Get this through you thick, ignorant skull:

    The exploit in the beta version has been addressed and fixed, prior to the report, so there is no vulnerability or exploit in the new release.

    I made the letters big enough, JmZ, because you didn't catch it the first 5 times I REPEATED myself, so maybe this time, you will see it and read it and comprehend it (somehow, I doubt it though).

Page 3 of 7 FirstFirst 12345 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Help with DDLCMS
    By Darkstar in forum Forum and DDL Discussion
    Replies: 11
    Last Post: 23rd May 2011, 07:54 AM
  2. DDLCMS 3.2 help
    By FuBu in forum Forum and DDL Discussion
    Replies: 2
    Last Post: 16th Apr 2011, 02:52 PM
  3. help with ddlcms!
    By cyber-cliff in forum Technical Help Desk Support
    Replies: 5
    Last Post: 18th Feb 2011, 04:14 PM
  4. DDLCMS Someone help?
    By lonerunner in forum Forum and DDL Discussion
    Replies: 18
    Last Post: 18th Nov 2009, 01:20 AM

Tags for this Thread

BE SOCIAL