Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Protential security Hole
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Topic ClosedProtential security Hole

 Post Reply Post Reply
Author
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Direct Link To This Post Topic: Protential security Hole
    Posted: 16 January 2004 at 2:28pm

Hi guys,

this isn't a major security hole thought it would be wise to say..

say you have a password 4 charecters long ..

then if someone whats to get into your account and you dont have it in a folder outside the root folder ... ie they can download it....

they then can open the database.. look at the User_code and see what the last to letters are ...

say your password was help.  in the User_code it would have lp on the end.

so if someone really wanted to get in they would only have to look in a dictionary and go through all them.. you can tell how long the password is by looking at the salt code .... also common words they would try ..

the only thing i can suggest is take out the last 2 charecters from the usercode or use part of the encrypted password...

i would like to say it would take time to hack in but if they wanted to they could....

i know its  a bit far fetched but its a protential security hole

Back to Top
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Direct Link To This Post Posted: 16 January 2004 at 2:49pm
Change the extension of the access db from .mdb to .asp (and also the connection strings). The access engine will still open it and work with it, but when someone tries to download it, the web server will try to run it as an asp script and return an error.

Lead me not into temptation... I know the short cut, follow me.
Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Direct Link To This Post Posted: 16 January 2004 at 2:53pm
i use it in a private directory ... but i thought i would say about it ... for those that don't use a private directory ...
Back to Top
Badaboem View Drop Down
Senior Member
Senior Member


Joined: 12 April 2002
Location: Netherlands
Status: Offline
Points: 600
Direct Link To This Post Posted: 16 January 2004 at 3:01pm
iis 6.0 should take car of this as well. Meta base does not allow files with mdb extension to be downloaded etc. You can allow or disallow extension types yourself.
Back to Top
MadDog View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 01 January 2002
Status: Offline
Points: 3008
Direct Link To This Post Posted: 16 January 2004 at 3:26pm

Read the documentation and you wont have any security problems.

Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Direct Link To This Post Posted: 16 January 2004 at 3:52pm
I am sure DJ Air knows the documentation and the forum fairly well, well enough that he is just pointing it out as a suggestion to remove the last two letters of the passoword from the user code.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Direct Link To This Post Posted: 16 January 2004 at 6:16pm
This was fixed/changed quite a few versions ago.

The way the user code is created was changed to containg the user name then appended to the end of it is a set of 10 random letters and numbers.

If this is not the case in your forum, try updating to the latest version.


Edited by -boRg-
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.