Jump to content

[SOLVED] Game Hubs on My site "Security Check" Please Beta Test it?


Recommended Posts

2n24pag.png

 

On My site http://wiicharged.com I have made the game hubs option.  Right now the options that I'm wanting you to test out are the create a hub and join a hub option.

 

The hub can be found here http://wiicharged.com/index.php?action=hubs

 

First thing to test security:

 

Make the hubs. 

 

http://wiicharged.com/index.php?action=hubs;sa=make;

 

How this works is when they create a hub the first step actually creates the folder and the second step copyies the main "hub" files from a directory to their folder.  When they think their confirming it or whatever (clever  ;D )

 

Second thing to test security

 

Join the hubs/actual hub itself

 

http://wiicharged.com/index.php?action=hubs;sa=join;

 

The user types in their "hub ID" and it pops up their "hub"  Which is a flash file that writes to a txt file.

 

 

 

 

Don't bash it up too much.  It's my first script and I plan to add more later.  As for the visual aspect of it.  I'm not done.  I just tried to put the main stuff in there (the script)  Please tell me how I can improve the security of my script before I release it?  Thanks!  ;D

Dammint I guess it wasn't secure.  Some people made some stuff that I didn't want and I was "Hacked" I guess.  On the folders option they made it and now I can't delete it.  My site is on maintenece now.  Thanks guys I really appreciate it. 

Okay I managed to delete the stuff before it could do any damage.  Once again thank you for whoever was doing that.  It even screwed up the chat.  Anyways....can someone help me make this more secure.  It's apparently easy to get into because within 30 seconds of opening this thread it happened  ;D

Admin Access:

http://www.wiicharged.com/hubs/hubs(backup).html contains your username and password.

 

Cross Site Scripting:

There is Cross Site Scripting if the hub name contains ">code.

 

Directory Transversal:

There is Directory Transversal if the hub name contains ../

 

Full Path Disclosure:

http://www.wiicharged.com/hubchat/hubex/shout.php

Warning: Cannot modify header information - headers already sent by (output started at /home/wiicharg/public_html/hubchat/hubex/shout.php:4) in /home/wiicharg/public_html/hubchat/hubex/shout.php on line 9

 

Warning: Cannot modify header information - headers already sent by (output started at /home/wiicharg/public_html/hubchat/hubex/shout.php:4) in /home/wiicharg/public_html/hubchat/hubex/shout.php on line 10

 

Warning: Cannot modify header information - headers already sent by (output started at /home/wiicharg/public_html/hubchat/hubex/shout.php:4) in /home/wiicharg/public_html/hubchat/hubex/shout.php on line 11

 

Full Path Disclosure:

http://www.wiicharged.com/hubchat/insert.php

Warning: mkdir() [function.mkdir]: File exists in /home/wiicharg/public_html/hubchat/insert.php on line 6

 

Full Path Disclosure:

http://www.wiicharged.com/hubchat/shout.php

Warning: Cannot modify header information - headers already sent by (output started at /home/wiicharg/public_html/hubchat/shout.php:4) in /home/wiicharg/public_html/hubchat/shout.php on line 9

 

Warning: Cannot modify header information - headers already sent by (output started at /home/wiicharg/public_html/hubchat/shout.php:4) in /home/wiicharg/public_html/hubchat/shout.php on line 10

 

Warning: Cannot modify header information - headers already sent by (output started at /home/wiicharg/public_html/hubchat/shout.php:4) in /home/wiicharg/public_html/hubchat/shout.php on line 11

 

Full Path Disclosure:

http://www.wiicharged.com/hubchat/test.php

Warning: mkdir() [function.mkdir]: File exists in /home/wiicharg/public_html/hubchat/test.php on line 3

 

Full Path Disclosure:

http://www.wiicharged.com/hubs/table.php

Warning: mysql_connect() [function.mysql-connect]: Access denied for user 'hub'@'localhost' (using password: YES) in /home/wiicharg/public_html/hubs/table.php on line 6

 

Full Path Disclosure:

http://www.wiicharged.com/hubs/put.php

Warning: mysql_connect() [function.mysql-connect]: Access denied for user 'wiicharg_smf2'@'localhost' (using password: YES) in /home/wiicharg/public_html/hubs/put.php on line 3

Access denied for user 'wiicharg_smf2'@'localhost' (using password: YES)

 

Full Path Disclosure:

http://www.wiicharged.com/hubs/insert.php

Warning: mkdir() [function.mkdir]: File exists in /home/wiicharg/public_html/hubs/insert.php on line 6

 

Full Path Disclosure:

http://www.wiicharged.com/hubs/database.php

Error creating database: Access denied for user 'wiicharg_hubs'@'localhost' to database 'my_db'

 

PHP Source Code Disclosure:

http://www.wiicharged.com/hubs/hubs(backup).html

 

PHP Source Code Disclosure:

http://www.wiicharged.com/hubchat/shoutfile.txt

 

User Enumeration:

http://www.wiicharged.com/~root

 

User Enumeration:

http://www.wiicharged.com/~wiicharg

 

You can create folders in http://www.wiicharged.com/hubchat/ if the hub name is set to the folder name.

 

You can create folders in any directory if the hub name is set to ../foldername.

 

You can create txt files in http://www.wiicharged.com/hub/ on http://www.wiicharged.com/hubs/1.php

phpSensei

 

 

You took nearly $500 from me for a project and you have not done anything or even contacted me.

Send me my money back right now or I will contact the police, dont mess with me!

You come online like its nothing, I done some research and found others you have scammed also out of money.

 

Do not test me!  Send me every single penny back or you will be going to jail!

phpSensei

 

 

You took nearly $500 from me for a project and you have not done anything or even contacted me.

Send me my money back right now or I will contact the police, dont mess with me!

You come online like its nothing, I done some research and found others you have scammed also out of money.

 

Do not test me!  Send me every single penny back or you will be going to jail!

 

Maybe that'll teach you to pay upfront, aye? :P

phpSensei

 

 

You took nearly $500 from me for a project and you have not done anything or even contacted me.

Send me my money back right now or I will contact the police, dont mess with me!

You come online like its nothing, I done some research and found others you have scammed also out of money.

 

Do not test me!  Send me every single penny back or you will be going to jail!

 

Who the hell are you?

 

The only person I am working with right now is Unik Design you jack ass...

 

I know who this is, and its not working.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.