darkfreaks Posted February 11, 2008 Share Posted February 11, 2008 http://vampirecity.cx-music.com/ Link to comment https://forums.phpfreaks.com/topic/90532-test-security/ Share on other sites More sharing options...
agentsteal Posted February 11, 2008 Share Posted February 11, 2008 Array: http://vampirecity.cx-music.com/covensimwith.php?u[] Array: http://vampirecity.cx-music.com/friendswith.php?u[] Array: http://vampirecity.cx-music.com/friendsof.php?u[] Array: http://vampirecity.cx-music.com/contest.php?contest[] Cross Site Scripting: There is Cross Site Scripting if the Expect header contains code. Full Path Disclosure: http://vampirecity.cx-music.com/includes/footer.php Warning: main(googlebottom.php) [function.main]: failed to open stream: No such file or directory in /home/www/vampirecity.cx-music.com/includes/footer.php on line 6 Full Path Disclosure: http://vampirecity.cx-music.com/forum/includes/footer.php Warning: main(googlebottom.php) [function.main]: failed to open stream: No such file or directory in /home/www/vampirecity.cx-music.com/forum/includes/footer.php on line 3 Warning: main() [function.include]: Failed opening 'googlebottom.php' for inclusion (include_path='.:/usr/local/lib/php') in /home/www/vampirecity.cx-music.com/forum/includes/footer.php on line 3 Full Path Disclosure: http://vampirecity.cx-music.com/includes/commentsadd.php Warning: main() [function.include]: Failed opening 'config.php' for inclusion (include_path='.:/usr/local/lib/php') in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 2 Warning: mysql_real_escape_string() [function.mysql-real-escape-string]: Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2) in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 4 Warning: mysql_real_escape_string() [function.mysql-real-escape-string]: A link to the server could not be established in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 4 Warning: mysql_query() [function.mysql-query]: Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2) in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 6 Warning: mysql_query() [function.mysql-query]: A link to the server could not be established in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 6 Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 8 Warning: mysql_close(): no MySQL-Link resource supplied in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 10 Warning: main(includes/footer.php) [function.main]: failed to open stream: No such file or directory in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 136 Warning: main() [function.include]: Failed opening 'includes/footer.php' for inclusion (include_path='.:/usr/local/lib/php') in /home/www/vampirecity.cx-music.com/includes/commentsadd.php on line 136 Full Path Disclosure: http://vampirecity.cx-music.com/includes/usersonline.php Parse error: parse error, unexpected T_VARIABLE in /home/www/vampirecity.cx-music.com/includes/usersonline.php on line 7 Full Path Disclosure: There is Full Path Disclosure if the PHPSESSID cookie is set to an invalid value. Warning: session_start() [function.session-start]: The session id contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,' in /home/www/vampirecity.cx-music.com/includes/header2.php on line 10 Warning: session_start() [function.session-start]: Cannot send session cookie - headers already sent by (output started at /home/www/vampirecity.cx-music.com/includes/header2.php:10) in /home/www/vampirecity.cx-music.com/includes/header2.php on line 10 Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/www/vampirecity.cx-music.com/includes/header2.php:10) in /home/www/vampirecity.cx-music.com/includes/header2.php on line 10 Warning: Cannot modify header information - headers already sent by (output started at /home/www/vampirecity.cx-music.com/includes/header2.php:10) in /home/www/vampirecity.cx-music.com/includes/header2.php on line 11 Warning: session_start() [function.session-start]: The session id contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,' in /home/www/vampirecity.cx-music.com/includes/header2.php on line 10 Warning: session_start() [function.session-start]: Cannot send session cookie - headers already sent by (output started at /home/www/vampirecity.cx-music.com/includes/header2.php:10) in /home/www/vampirecity.cx-music.com/includes/header2.php on line 10 Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/www/vampirecity.cx-music.com/includes/header2.php:10) in /home/www/vampirecity.cx-music.com/includes/header2.php on line 10 Warning: Cannot modify header information - headers already sent by (output started at /home/www/vampirecity.cx-music.com/includes/header2.php:10) in /home/www/vampirecity.cx-music.com/includes/header2.php on line 11 Includes Directory: http://vampirecity.cx-music.com/includes/ Includes Directory: http://vampirecity.cx-music.com/forum/includes/ Log File: http://vampirecity.cx-music.com/images/WS_FTP.LOG Link to comment https://forums.phpfreaks.com/topic/90532-test-security/#findComment-464215 Share on other sites More sharing options...
darkfreaks Posted February 11, 2008 Author Share Posted February 11, 2008 i was mainly worried about the XSS i disabled Javascript code no worries thanks. Link to comment https://forums.phpfreaks.com/topic/90532-test-security/#findComment-464225 Share on other sites More sharing options...
Acs Posted February 12, 2008 Share Posted February 12, 2008 As a side note: The site looks awful Link to comment https://forums.phpfreaks.com/topic/90532-test-security/#findComment-464704 Share on other sites More sharing options...
juke Posted February 20, 2008 Share Posted February 20, 2008 As a side note: The site looks awful Yeah, doesn't look the best mate. Link to comment https://forums.phpfreaks.com/topic/90532-test-security/#findComment-471939 Share on other sites More sharing options...
freenity Posted February 21, 2008 Share Posted February 21, 2008 agentsteal Do you use any program to test sites??? Link to comment https://forums.phpfreaks.com/topic/90532-test-security/#findComment-473093 Share on other sites More sharing options...
Recommended Posts