Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - £25 Reward
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

£25 Reward

 Post Reply Post Reply Page  <1 234
Author
Scotty32 View Drop Down
Moderator Group
Moderator Group


Joined: 30 November 2002
Location: Manchester, UK
Status: Offline
Points: 1682
Post Options Post Options   Thanks (0) Thanks(0)   Quote Scotty32 Quote  Post ReplyReply Direct Link To This Post Posted: 08 July 2005 at 7:13am
Quote I think they figured a way to send the messages outside the system somehow.


dont you offer 'reselling'?

couldnt they of used that as a way of doin it?
S2H.co.uk - WebWiz Mods and Skins

For support on my mods + skins, please use my forum.
Back to Top
theSCIENTIST View Drop Down
Senior Member
Senior Member


Joined: 31 July 2003
Location: United Kingdom
Status: Offline
Points: 440
Post Options Post Options   Thanks (0) Thanks(0)   Quote theSCIENTIST Quote  Post ReplyReply Direct Link To This Post Posted: 09 July 2005 at 1:07pm
Right, first I would like to say that MD5 can be cracked, however I don't think that was the scenario here since you are sufixing it with a salt, then adding the password to the cookie is a really bad idea, the username is fine, as it can be found out anyway.

Quote I think they figured a way to send the messages outside the system somehow.

Humm, what steps are you tacking against CSRF? That's when people build their own forms and submit data with their own custom forms and not yours, therefore bypassing a few things that could be crutial and also sending stuff along that could have nasty effects, I'm actually developing my own way to prevent this that will involve checking for referee and generating a form token then when receiving data I would compare the token, meaning whether it came from my form or not, this is very important, you must make sure people submit data with your form only.
Back to Top
dfrancis View Drop Down
Senior Member
Senior Member


Joined: 16 March 2005
Location: United States
Status: Offline
Points: 442
Post Options Post Options   Thanks (0) Thanks(0)   Quote dfrancis Quote  Post ReplyReply Direct Link To This Post Posted: 09 July 2005 at 2:24pm
Originally posted by theSCIENTIST theSCIENTIST wrote:

Right, first I would like to say that MD5 can be cracked, however I don't think that was the scenario here since you are sufixing it with a salt, then adding the password to the cookie is a really bad idea, the username is fine, as it can be found out anyway.

Quote I think they figured a way to send the messages outside the system somehow.

Humm, what steps are you tacking against CSRF? That's when people build their own forms and submit data with their own custom forms and not yours, therefore bypassing a few things that could be crutial and also sending stuff along that could have nasty effects, I'm actually developing my own way to prevent this that will involve checking for referee and generating a form token then when receiving data I would compare the token, meaning whether it came from my form or not, this is very important, you must make sure people submit data with your form only.
 
YES! That's what I was thinking too!!!
 
However, that would have been easily identifiable in the logs I would think.
 
The for token sounds like a great idea... I've read something on this before but can't remember where... darnit.
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 09 July 2005 at 4:03pm
Nothing of any value came from the logs.

I think someone found out my password and wrote their own scripts to send SMS messages.
Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 13 July 2005 at 2:45am
does your site store login information so they don't have to log in when they come back?.. it's possible that you logged on somewhere public and somebody sat down and went o boy! administrator access!
Back to Top
 Post Reply Post Reply Page  <1 234

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.