Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - ASP hack challange..
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

ASP hack challange..

 Post Reply Post Reply
Author
jimidy View Drop Down
Groupie
Groupie


Joined: 05 October 2003
Status: Offline
Points: 54
Post Options Post Options   Thanks (0) Thanks(0)   Quote jimidy Quote  Post ReplyReply Direct Link To This Post Topic: ASP hack challange..
    Posted: 31 January 2004 at 10:08pm

I've made an admin part of my site secure..  was wondering if anyone was bored to see if they could hack my site and retrieve my password..  Obviously I don't expect you to give me the whole password for moral reasons (it could be anyones site!)  But if you can get the password, Post the first 2 charcaters here, and also proposed solutions to making it more secure..

Thanks, and good luck white hats..

http://cms-stu-iis.gre.ac.uk/wn008/project/site/admin/ 

www.srp.me.uk
Back to Top
fernan82 View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 17 November 2002
Location: United States
Status: Offline
Points: 362
Post Options Post Options   Thanks (0) Thanks(0)   Quote fernan82 Quote  Post ReplyReply Direct Link To This Post Posted: 31 January 2004 at 10:59pm
Why don't you say where/how you're storing the password and we'll tell you if it's safe or not. If it's on a database server like MSSQL then it should be safe. If it's hardcoded on your source code or a file database then depending on the server setup somebody might be able to get it if it's a shared server.
FeRnAN
Back to Top
jimidy View Drop Down
Groupie
Groupie


Joined: 05 October 2003
Status: Offline
Points: 54
Post Options Post Options   Thanks (0) Thanks(0)   Quote jimidy Quote  Post ReplyReply Direct Link To This Post Posted: 01 February 2004 at 6:21am

I felt if it was unsecure you would be able to tell me..   I'll leave it a couple of days, and if no one gets it tell you how the security is done to see if it can be broken then..

www.srp.me.uk
Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 01 February 2004 at 5:42pm
you would probably want to write some type of script to limit the incorrect password to like 3 tries... i could write a script right now to go through all the possible passwords (a.k.a. brute force attack)
Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 01 February 2004 at 5:48pm
otherwise you're admin screen's well secured... i can't download the processing file with a download manager, and i'm not getting a directory listing or ftp options
Back to Top
Necronom View Drop Down
Groupie
Groupie


Joined: 19 October 2001
Location: United States
Status: Offline
Points: 116
Post Options Post Options   Thanks (0) Thanks(0)   Quote Necronom Quote  Post ReplyReply Direct Link To This Post Posted: 02 February 2004 at 10:25am

How does a DL man get around the restrictions of ASP. Are you saying that something like DAP can save the source ASP file?

. necronom .

Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 02 February 2004 at 6:03pm
a directory listing shows you all the files in the directory (i'll stop acting like you guies are two now...). Sometimes you can use other files that aren't asp to use as an indirect download source (hence, downloading the raw ASP file)
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 February 2004 at 3:47am
You might want to pass across somthing like the ASP session ID in a hidden field and then check it matches before processing the password, this would prevent a hacker using a password cracking tool from a remote site.

Having a username field as well will also help as the hackers would also need to crack the username field as well as the password.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.