Jump to content

Hack my website


talor123

Recommended Posts

hey,recently ive created a website from scratch.. just the main files like registering user accounts, logging in ect... before i go ahead with all the css and making it look good i would like anyone who has the time to see if they can get around my scripts... eg:  use php injections..  view usernames/passwords, try editing the pages any form of hacking it.. and well if you can. please tell me how so i can patch it :) lol

 

heres some info to use on my webpage if u want

 

Username: bob

Password: 12345

 

and heres my webpage

 

http://talor.freehostia.com/

 

thank you!

 

ps: tell me if you cant hack it.. and just ask if your having trouble with anything

Link to comment
https://forums.phpfreaks.com/topic/114411-hack-my-website/
Share on other sites

not that i'm about to spend all day but, if you enter something in both fields, it'll inform me that the username is doesn't exist, but if you fill both, even with username 'bob' then it informs you 'Invalid Username or Password.', because of this I could brute force until I found a username (if they wern't already displayed somewhere)

Link to comment
https://forums.phpfreaks.com/topic/114411-hack-my-website/#findComment-588343
Share on other sites

same response whatever they do...

 

This is an interesting one - right off the bat I agree with you, the response should be same regardless of whether it's the password or the userID that's incorrect. We agree because we're coders and we think logically ( ;) ). But usability experts completely disagree with us, which I was pretty surprised to learn: http://www.uie.com/articles/account_design_mistakes_part2/ (see "Mistake 13").

 

I think the user/pass incorrect login dialogue is one of those places where you're going to have to look at your audience to decide which is most appropriate - I do believe that the secure way is the best way, but if it's going to put off users who don't understand (or who aren't interested) in the security implications, then you gotta choose between the two.

Link to comment
https://forums.phpfreaks.com/topic/114411-hack-my-website/#findComment-588362
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.