Jump to content
  • Sign Up

STAR

Collaborator
  • Posts

    466
  • Joined

  • Last visited

  • Days Won

    1

Everything posted by STAR

  1. Any ideas where I sort this out Rating failed: {"error":"You have reached your quota of positive votes for the day"} I had a look around in admin panel can't seem to find it
  2. Hi Guys I have small issue I have latest version of TopX stats installed I have few issues 1. first of all gaps between names are way to big is there a way to make them less gappy ? ( please see image with small arrows where I mean by gaps ) 2. If you see image you will see user info I have highlited I want it to move down just above where user stats are and move TopX stats up closer to staff room bar Can some one advice me how can i achieve this? Here is image Thank you
  3. Thanks Justin do you know which version do i need as there are 2 of them in downloads? Thank you again for your reply
  4. Thanks for reply Can you please direct me to correct mod I need as i did what you said and it gives out error as seen here. Thank you for your reply
  5. I'm glad it helped you if you need more help please let me know. Good Luck
  6. Hi Guys I'm having issues with reputation system I'm running IPB 3.4.5 And for some reason reputation does not show up in thread like it use to with + and - there is just nothing there As you can see it here I'm using acording to my applications (SOS30) Reputation Points v1.0.1 and [AH30] Reputation v1.0.2 Acording to my hooks Can some one please help me out how to get it to show up liek it use to with small green + and and small red - in posts. Thank you
  7. Hi usually I charge for this service but I'm offering free security scan of your own site, it does not matter what script you use. If you have issues with hackers or worried about how secure your site is drop mea PM and I will give you a ditailed information on where the security problem is located, what it does and what needs to be done to fix it. If you find my help usefull you can donate to WebFlake to say thank you Please note prove of ovnership of the site might be required ( I will not scan the site for you just so you can hack it ) Also depending on website size it can take anywhere from 1 hour to 6 hours. Thanks and see you all round. Here is example of 1 of clients scaned site so you can get better idea. Blind SQL Injection 1. Vulnerability description Blind SQL Injection This script is possibly vulnerable to SQL Injection attacks. SQL injection is a vulnerability that allows an attacker to alter backend SQL statements by manipulating the user input. An SQL injection occurs when web applications accept user input that is directly placed into a SQL statement and doesn't properly filter out dangerous characters. This is one of the most common application layer attacks currently being used on the Internet. Despite the fact that it is relatively easy to protect against, there is a large number of web applications vulnerable. This vulnerability affects /topic/1012-%CF%80%CE%B1%CF%81%CE%BF%CF%85%CF%83%CE%B9%CE%B1%CF%83%CF%84%CE%B5-%CF%84%CE%BF-desktop-%CF%83%CE%B1%CF%82. Discovered by: Scripting (Blind_Sql_Injection.script). Attack details HTTP Header input client-ip was set to -1' or 58 = '56 headers Request GET /topic/1012-%CF%80%CE%B1%CF%81%CE%BF%CF%85%CF%83%CE%B9%CE%B1%CF%83%CF%84%CE%B5-%CF%84%CE%BF-desktop-%CF%83%CE%B1%CF%82 HTTP/1.1user-agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)client-ip: -1' or 58 = '56X-Requested-With: XMLHttpRequestCookie: PHPSESSID=e76de147dfe45cd368ee6bf9f1b3b304; session_id=google%3D664bba98b2028cb7b36f6ba3439ddbdf_sessionHost: fantastic-forum.infoConnection: Keep-aliveAccept-Encoding: gzip,deflateAccept: */* Response HTTP/1.1 200 OKServer: nginx/1.5.0Date: Mon, 01 Jul 2013 21:30:29 GMTContent-Type: text/html;charset=UTF-8Connection: keep-aliveX-Powered-By: PHP/5.3.25Cache-Control: no-cache, must-revalidate, max-age=0Expires: Sun, 30 Jun 2013 21:30:29 GMTPragma: no-cacheVary: Accept-EncodingSet-Cookie: session_id=37c1f21e9de10f14e1282aa45efcf459; path=/; domain=Removed; httponlySet-Cookie: modpids=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=RemovedContent-Length: 157260 HTML response [Your user agent does not support frames or is currently configured not to display frames. However, you may visit <A href="iframes/idf91.html">the related document.</A>] The impact of this vulnerability An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information. Depending on the back-end database in use, SQL injection vulnerabilities lead to varying levels of data/system access for the attacker. It may be possible to not only manipulate existing queries, but to UNION in arbitrary data, use subselects, or append additional queries. In some cases, it may be possible to read in or write out to files, or to execute shell commands on the underlying operating system. Certain SQL Servers such as Microsoft SQL Server contain stored and extended procedures (database server functions). If an attacker can obtain access to these procedures it may be possible to compromise the entire machine. How to fix this vulnerability Your script should filter metacharacters from user input. Alert 2. HTTP Parameter Pollution Vulnerability description This script is possibly vulnerable to HTTP Parameter Pollution attacks. HPP attacks consist of injecting encoded query string delimiters into other existing parameters. If the web application does not properly sanitize the user input, a malicious user can compromise the logic of the application to perform either clientside or server-side attacks. Affected items [*]/index.php/ The impact of this vulnerability The impact depends on the affected web application. An attacker could [*]Override existing hardcoded HTTP parameters [*]Modify the application behaviors [*]Access and, potentially exploit, uncontrollable variables [*]Bypass input validation checkpoints and WAFs rules How to fix this vulnerability The application should properly sanitize user input (URL encode) to protect against this vulnerability.
  8. Fixing my own site :)

  9. Best way to tell where the images is located that you want to change would be.. 1. right click image in question 2. select image info ( this will display full path of the image in question as well as name of the actual image ) 3. Change the image as you desire. Hope you have better understanding of how t9o locate images in question that you want to change. Good luck
  10. STAR

    Hello

    Hi LucianDev, Welcome to WebFlake I'm also new here and this is nice and friendly site Enjoythe forums and don't forget to read the rules if you need any help.
  11. Thsi is small guide writen by me to help some people stay safe online and what to look out for. It is only a guide to help. I will explain some of the methods used by hackers and give you tips on ways you can stay safe. Email Hacking: 1. Hotmail account or other email account hacking. it is easy to get access to peoples emails by simple rest trick, Let me explain.... A hacker can request password rest by answering your security questions, it is very easy if you sign up to Facebook or other social networking website to get relevant information required to rest your password. It is always advised to do all the following when creating new email. Security Or Creating Secure passwords: 1. If secret question is lets say teachers name: you put in your pets name instead. meaning nothing relative to actual question. 2. Always use mixed special characters for example. if your password is starwars use $tArwAr5 or any mixed combination of capital letter in middle or special key like !"£$%%^&*()_) in side of it, password is case sensitive and it is very hard to crack even using tools like bruiteforcer. It is also advised you add some sort of year or numbers, in front or end of the password. this will create 100% secure password that will be almost impossible to hack. Even when following above method, you still not secure!Llet me explain why..... Hacker can also create what's called "phishing page " What is phishing? Phishing page is designed to be identical site of the target so lets say "facebook" you might receive email telling you to update some account information, could be from your bank, paypal and so on, it has link everything will look legit. The only way to know for sure is move the mouse over the link you have in your email, on bottom of your screen it will say the real url so, if it's from facebook it should be www.facebook.com not www.123.facebook.com same goes for other emails you might get. "NEVER CLICK THE LINK IN THE EMAIL" always go to site by typing it in to your browser. Drive By Hacking: ( no not the gangster film ) Drive by is designed to infect the victim visiting specific website. You might come across site on Google, or one of the other site you use might of been hacked and have drive by installed, Best way to tell this is if you get Java Message telling you it's from Microsoft or trusted website. Never agree to Java install on any website you might get message to do so.( yes this goes for porn sites also, they are very common to have drive by's on it ) P2P Downloading tool: ( P2P Meaning peer to peer ) Don't ever use any tool to download music, thing's like "Kazza" " Morphyos " "BareShare" and so on nor let any one in family use this kinda tool to download anything, this website are full of viruses and non of the P2P Tools out there are any good. ( If you do feel in need to download or some one in your house hold does tell them to google up "warez" site there are tons of them out there are they are virus free as they get moderated. ) YOU can also download videos from youtube by typing you front of youtube "save" so it's savetube.com. Don't ever let any one use any kinda downloading tool to download anything, even with virus protection it will not help as chances are it will be encrypted. Recommendation: Download Malwarebytes Download Page It is free and it's very powerful, if you want to pay for it you will get much better functions. Above is just a small guide to help you understand better about safe way of cyber surfing, It is just an advice use it or not will be totally up to you.
  12. Hi Welcome I'm also new here and this is nice and friendly site Enjoythe forums and don't forget to read the rules if you need any help.
  13. STAR

    Hi

    Hi Welcome I'm also new and yes it is great and friendly site Enjoy the forums and don't forget to read the rules if you need any help.
  14. Thank you for all the warm welcomes
  15. Do you have diamensions you want or same as above?
  16. Just signed up as I love some of the downloads you guys have here. I'm Breez owner of cyber security forums I'm 32 and really easy going guy. I'm also really handy with GFX Design so if any one needs any help give me a shout So yeah you guys might see me around I will also post some guides for members on how to stay safe onlien and so on Thanks and see you all round
×
×
  • Create New...