Jump to content
MakeWebGames

Upload Image & Display $10


Haunted Dawg

Recommended Posts

Hi There,

Description:

Users may upload an image and then it will be displayed on there profile & under there uploaded pictures.

Includes:

1.- 1 .php file.

2.- 2 Sql's.

3.- couple lines of codes for viewuser.php.

Price: $10

Copies: 10

Paypal: [email protected]

Preview: www.ganstawars.net

Owners:

Me & Iseeyou, We decided to make this and now we both have the rights to sell and we dont share the profits we make.

Thanks.

Link to comment
Share on other sites

Re: Upload Image & Display $10

 

i can assure you iso's mod has far better security than yours.

Who actualy told iso that his mod can be easy hacked?

A = ME

Now seriusly his is not more secure there for mine actualy is like 20 lines of code when his is like 50+ mine only allows .jpg .gif .JPG .bmp and so on now remmember iso's one i could easly add a .php file with ease with mine not even and now again there is a way i can upload a .php file via iso's & mine just by using a single % inbetween so your image will appear like:

shell.php%$".jpg

now again it will only read the last sequence wich is .jpg allowing me to actualy upload the image but mean time its a shell! so get that in your thick mind!

Link to comment
Share on other sites

Re: Upload Image & Display $10

Lmfao...so "Not so good" means it's only 99.9% secure. You're smoking crack dude...and please quit using the "Nothing can ever be 100% secure" crap as an excuse.

Not to mention...I would rely more on Iso's coding than anything you made...That's just me though. :-D

Link to comment
Share on other sites

Re: Upload Image & Display $10

i brought this mod not so long ago and realied it not secure as they can still upload shells! but i hva emanaged to secure this even more i even offerd to send the part that needed to be secured! as its only a little fixs that is needed ! as the users can just do this

example:

sh3ll.php%%00.jpeg

with this they can upload a shell under a jpeg or gif and simple bugger up you site!

all by doing :

http://domain.com/picprofile/sh3ll.php%%00.jpeg

 

so i have manged to simply stop this from happening and also fixed for people using Vista as i orrigenly could not upload simply jpeg. so if you would like the little fix jst simply pm me and ill give you the fix :)

Link to comment
Share on other sites

Re: Upload Image & Display $10

Hmmm...

I don't see how my mod is insecure, as... Even if you attempt to upload your shell...

It doesn't matter? PHP re-creates the image using PHP, then deletes the original script uploaded, if it cannot re-write (if its a shell) it will stop the process and not upload....

I worked quite a lot on that mod, with various research in PHP, helped me discover a lot more functions.

I doubt you can upload your renamed shell... :wink:

Ok, so lets test this on the uploader i made (the free secure one)...

Attempt to upload: sh3ll.php%%00.jpeg

Result:

The image you are trying to upload seems to be corrupt please try again!

Back

:roll:

Link to comment
Share on other sites

Re: Upload Image & Display $10

security is not good for the following reason(s)

1) uploading via there PC to server (possible sql injection) to upload a shell and screw up your site.

solution..... put a htaccess file in to disable execution or set the chmod on folder to allow upload but no execution of files.

Link to comment
Share on other sites

Re: Upload Image & Display $10

 

security is not good for the following reason(s)

1) uploading via there PC to server (possible sql injection) to upload a shell and screw up your site.

solution..... put a htaccess file in to disable execution or set the chmod on folder to allow upload but no execution of files.

 

Yep, I've seen you posted something like this under PHP section, been using for a while now under profilepics. I'll include into the mod instructions for extra security.

 

# AddHandler cgi-script .php .pl .py .jsp .asp .htm .shtml .sh .cgi
Options -ExecCGI
Link to comment
Share on other sites

Re: Upload Image & Display $10

 

Can you please stop criticizing his work please

At least he's bothered to put it up

I would buy it, just don't want anyone uploading shells to hack my game lol

SOrry

Dude.. did you even read this thread through out?

Or did you just see one post and decide to stick up for killah, with some dumb ass post?

If you don't want shell's just use this: http://criminalexistence.com/ceforums/h ... 385#p51385

Its free! Something you can afford! :-o

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...