zulugogogo Posted September 25, 2009 Share Posted September 25, 2009 Hi, i am not sure how to go about asking someone to see if my site is secure from ... well what ever is out there! it is a work in progress and i would appreciate it if someone can hack in, and if so tell me i am new to php and am totally confussed, another guy installed the scripting and then... no more contact so i am going through it slowly. looking at the security part of this site i have searched for MD5 within the scripts and i see them and also mysql_real_escape_string. However i notice some sites are using an ip something or another. So before anything else, can someone just walk in and destroy it? Your help is appreciated. ha ha forgot to put the site name in www.123omg.com Thanks loads Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/ Share on other sites More sharing options...
mayfair Posted September 25, 2009 Share Posted September 25, 2009 Well I can't even attempt to login because your code doesn't work properly! Fatal error: Class 'PHPBB_Login' not found in /home/zulugogo/public_html/123omg.com/app/controllers/users.php on line 131 Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-924882 Share on other sites More sharing options...
zulugogogo Posted September 25, 2009 Author Share Posted September 25, 2009 oh sorry about that, at what pont do you get this error? as i dont get it at all, even if i login as an existing user. I can supply you with a user name and password if that helps. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925035 Share on other sites More sharing options...
nrg_alpha Posted September 25, 2009 Share Posted September 25, 2009 zulugogogo, I moved your thread to this forum. Please make note of this forum for future test requests. Also, please read this forum's rules and ensure everything complies with it. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925056 Share on other sites More sharing options...
zulugogogo Posted September 26, 2009 Author Share Posted September 26, 2009 ok, point taken, can anyone suggest a good Free exploit scanner i can get to test my site. An d i wont ask for people to hack into the site. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925208 Share on other sites More sharing options...
Garethp Posted September 26, 2009 Share Posted September 26, 2009 You are allowed to ask people to hack into your site, provided that it's yours Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925310 Share on other sites More sharing options...
darkfreaks Posted September 26, 2009 Share Posted September 26, 2009 if you use Mozilla Firefox check out the Access Me,SQL Inject Me and XSS Me plugins Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925406 Share on other sites More sharing options...
zulugogogo Posted September 26, 2009 Author Share Posted September 26, 2009 hi, thanks for the firefox stuff. I am concerned now that i have asked people to hack my site and do not realise the consiquence of this. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925513 Share on other sites More sharing options...
zulugogogo Posted September 26, 2009 Author Share Posted September 26, 2009 tried the firefox stuff out and it seemed good the XSS Me seemed to pull a lot of HTTP Method: SECCOMP errors, so i tried it on some other sites and they too seem to suffer from this problem. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925529 Share on other sites More sharing options...
darkfreaks Posted September 27, 2009 Share Posted September 27, 2009 you mean Access me? XSS me only pulls up XSS exploits anyhow thats fixable put the following in your .htaccess file in the root directory. RewriteCond %{REQUEST_METHOD} !^(GET|HEAD|OPTIONS|POST|PUT) RewriteRule .* - [F] Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925597 Share on other sites More sharing options...
MadTechie Posted September 27, 2009 Share Posted September 27, 2009 Well I can't even attempt to login because your code doesn't work properly! Fatal error: Class 'PHPBB_Login' not found in /home/zulugogo/public_html/123omg.com/app/controllers/users.php on line 131 oh sorry about that, at what pont do you get this error? as i dont get it at all, even if i login as an existing user. I can supply you with a user name and password if that helps. On the login button Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-925613 Share on other sites More sharing options...
zulugogogo Posted September 27, 2009 Author Share Posted September 27, 2009 Thanks darkfreaks, i have made the change. As for logging in.... no idea why that is, am looking into it. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-926089 Share on other sites More sharing options...
shtarkel Posted October 28, 2009 Share Posted October 28, 2009 If someone can hack my site mydreamzone.net, to see if the updates i 've made are working properly, thanks! I've made a copy og it so do not hesitate, and if you can say whare are the security holes it would be greatful Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-946282 Share on other sites More sharing options...
MadTechie Posted October 28, 2009 Share Posted October 28, 2009 shtarkel, please create a new thread and read the conditions Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-946288 Share on other sites More sharing options...
shtarkel Posted October 28, 2009 Share Posted October 28, 2009 thats the proof. if you need something else just wrute it down here Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-946301 Share on other sites More sharing options...
MadTechie Posted October 28, 2009 Share Posted October 28, 2009 What's the proof ? An image doesn't prove anything! shtarkel, please create a new thread and read the conditions Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-946306 Share on other sites More sharing options...
448191 Posted November 18, 2009 Share Posted November 18, 2009 Why do I see threads with "don't break it" in the thread title... I say break away. If the OP was stupid enough to post a production site they deserve being taught a lesson. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-960083 Share on other sites More sharing options...
MadTechie Posted November 18, 2009 Share Posted November 18, 2009 Very True, its like they don't have a backup or a sandbox.. its not like we have any higher access level than the rest of the people on the net! Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-960104 Share on other sites More sharing options...
Daniel0 Posted November 21, 2009 Share Posted November 21, 2009 What's the proof ? An image doesn't prove anything! shtarkel, please create a new thread and read the conditions Topics in this board a moderated. This means a staff member has manually approved this topic. Link to comment https://forums.phpfreaks.com/topic/175458-can-someone-hack-my-site-dont-break-it-though/#findComment-962427 Share on other sites More sharing options...
Recommended Posts