TalkPHP
 
 
Account Login
Latest Articles
» The basic usage of PHPTAL, a XML/XHTML template library for PHP
» Vulnerable methods and the areas they are commonly trusted in.
» Simple way to protect a form from bot
» The Basics On: How Session Stealing Works
» How to keep your forms from double posting data
IRC Channel
IRC Speech Bubble Join the friendly bunch on IRC...
(#TalkPHP on Freenode)

...Also available via a web interface.

See this thread for information on the TalkPHP Free Hugs Initiative™. Subject to availability.
Associates
Associates
CSS Tutorials
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 01-22-2009, 09:45 AM   #1 (permalink)
The Wanderer
 
Join Date: Sep 2008
Location: Tehran - Iran
Posts: 6
Thanks: 35
Y.P.Y is on a distinguished road
Bug Bug in Post thanks - not secure!

Hi,
I find a bug/vuln. in Thank plugin! Its not secure!
Plz check for updates(Patch).

http://www.talkphp.com/post_thanks.p..._thanks_add&u='

GL.
__________________
http://Yousha.Blog.ir/
Send a message via ICQ to Y.P.Y
Y.P.Y is offline  
Reply With Quote
The Following User Says Thank You to Y.P.Y For This Useful Post:
Yoosha (03-17-2010)
Old 02-04-2009, 01:52 AM   #2 (permalink)
La Vida es Sueño
Advanced Programmer Top Contributor 
 
Wildhoney's Avatar
 
Join Date: Sep 2007
Location: Oldham
Posts: 2,280
Thanks: 90
Wildhoney is on a distinguished road
Default

Thanks for pointing this out. However, hmm, I get a "Content Encoding Error" error for that. How does this URL differ from the one on the "Say Thanks" button, apart from you've substituted the p parameter for u?
__________________
The man who comes back through the Door in the Wall will never be quite the same as the man who went out.
Send a message via AIM to Wildhoney Send a message via MSN to Wildhoney Send a message via Yahoo to Wildhoney
Wildhoney is offline  
Reply With Quote
Old 02-04-2009, 08:37 AM   #3 (permalink)
The Wanderer
 
Join Date: Sep 2008
Location: Tehran - Iran
Posts: 6
Thanks: 35
Y.P.Y is on a distinguished road
Default

lol!
Iam not a hacker! But you know about hackers?
Do you think, Hackers uisng standard URL browsing??
This plugin is not secure(Patch needed) And this is a BUG!
GL.
__________________
http://Yousha.Blog.ir/
Send a message via ICQ to Y.P.Y
Y.P.Y is offline  
Reply With Quote
The Following User Says Thank You to Y.P.Y For This Useful Post:
Yoosha (03-17-2010)
Old 02-04-2009, 10:57 AM   #4 (permalink)
Moderateur
RegEx Guru PHP Guru Top Contributor Advanced Programmer 
 
Salathe's Avatar
 
Join Date: Apr 2007
Posts: 1,393
Thanks: 5
Salathe is on a distinguished road
Default

Please explain the actual vulnerability, what harm can be done?
Salathe is offline  
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help me secure this code? Aaron Absolute Beginners 16 06-25-2009 10:55 AM
Venerable methods and the applications they are commonly trusted in. Village Idiot Tips & Tricks 7 11-06-2008 07:36 AM
Secure pages?? marxx General 6 03-09-2008 08:49 AM
Secure AJAX Server Scripts trmbne2000 General 4 12-07-2007 01:14 AM


All times are GMT. The time now is 08:47 AM.

 
     

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Inactive Reminders By Icora Web Design