unidox Posted July 27, 2008 Share Posted July 27, 2008 I just finished the backend of the CMS to come. I am working on the template engine, and should have the front end in a few days. Please, I want all tips, feedback, I dont care how flammable it is, I want to make this better. Please try all normal stuff such as XSS, SQL Injection, ect I will be releasing beta once I finish the front end, so enjoy! www.pure-cp.com/beta/admin User: demo Pass: demo Thanks Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/ Share on other sites More sharing options...
darkfreaks Posted July 27, 2008 Share Posted July 27, 2008 Apache Mod_SSL SSL_Util_UUEncode_Binary Stack Buffer Overflow Vulnerability Vulnerability description This alert was generated using only banner information. It may be a false positive. A stack-based buffer overflow has been reported in the Apache mod_ssl module. This issue would most likely result in a denial of service if triggered, but could theoretically allow for execution of arbitrary code. The issue is not believed to be exploitable to execute arbitrary code on x86 architectures, though this may not be the case with other architectures. Affected mod_ssl versions (up to 2.8.17). This vulnerability affects mod_ssl. The impact of this vulnerability Denial of service and/or possible arbitrary code execution. Attack details Current version is mod_ssl/2.2.8 OpenSSL/0.9.8b mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Unknown How to fix this vulnerability Upgrade mod_ssl to the latest version. Apache Mod_SSL Log Function Format String Vulnerability Vulnerability description This alert was generated using only banner information. It may be a false positive. A format string vulnerability has been found in mod_ssl versions older than 2.8.19. Successful exploitation of this issue will most likely allow an attacker to execute arbitrary code on the affected computer. Affected mod_ssl versions (up to 2.8.18). This vulnerability affects mod_ssl. The impact of this vulnerability Denial of service and/or possible arbitrary code execution. Attack details Current version is mod_ssl/2.2.8 OpenSSL/0.9.8b mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Unknown How to fix this vulnerability Upgrade mod_ssl to the latest version. Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-600709 Share on other sites More sharing options...
darkfreaks Posted July 27, 2008 Share Posted July 27, 2008 Vulnerability description HTTP TRACE method is enabled on this web server. In the presence of other cross-domain vulnerabilities in web browsers, sensitive header information could be read from any domains that support the HTTP TRACE method. This vulnerability affects Web Server. The impact of this vulnerability Attackers may abuse HTTP TRACE functionality to gain access to information in HTTP headers such as cookies and authentication data. How to fix this vulnerability Disable TRACE Method on the web server. Password input type autocomplete enabled impact of exploit possible information disclosure affected files admin/login.php forums/index.php How to fix this vulnerability The password autocomplete should be disabled in sensitive applications. To disable autocomplete, you may use a code similar to: <INPUT TYPE="password" AUTOCOMPLETE="off"> Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-600710 Share on other sites More sharing options...
unidox Posted July 27, 2008 Author Share Posted July 27, 2008 Talking to my hosting company now to fix this. Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-600867 Share on other sites More sharing options...
darkfreaks Posted July 27, 2008 Share Posted July 27, 2008 let me know when those exploits are fixed unidox ill rescan to be sure Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-601176 Share on other sites More sharing options...
unidox Posted July 28, 2008 Author Share Posted July 28, 2008 Can I ask what you use to scan? Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-601206 Share on other sites More sharing options...
darkfreaks Posted July 28, 2008 Share Posted July 28, 2008 Acunetix why ??? Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-601224 Share on other sites More sharing options...
olie122333 Posted July 28, 2008 Share Posted July 28, 2008 Acunetix why ??? thanks lol it is brilliantly descriptive output Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-601606 Share on other sites More sharing options...
waynew Posted July 28, 2008 Share Posted July 28, 2008 I use the free version. Acunetix is the fo shizzle dawg. Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-601612 Share on other sites More sharing options...
darkfreaks Posted July 28, 2008 Share Posted July 28, 2008 I use the free version. Acunetix is the fo shizzle dawg. the free version only lets you scan XSS Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-601885 Share on other sites More sharing options...
waynew Posted July 29, 2008 Share Posted July 29, 2008 I know. I'm going to cry now. :'( Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-602501 Share on other sites More sharing options...
olie122333 Posted July 30, 2008 Share Posted July 30, 2008 No XSS Cross-Site-Scripting vunlebilitys. Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-603413 Share on other sites More sharing options...
darkfreaks Posted August 3, 2008 Share Posted August 3, 2008 the Mod SSL was a false alert ignore those :-\ Link to comment https://forums.phpfreaks.com/topic/116805-control-panel-for-clans/#findComment-606916 Share on other sites More sharing options...
Recommended Posts