Jump to content
MakeWebGames

Recommended Posts

Posted

Re: Hit-List [$10]

My shoutbox is secure from giving your self crystals, admin, money and other wise with the database, the only thing that can be done is refreshing in the shoutbox.

You claimed you fixed it? By adding a code that changed meta to mega? GO DREAM!

So as far as i know my shoutbox is pretty secure from exploiting the database, unless you can provide proof, by letting me test it, then ******!

Posted

Re: Hit-List [$10]

meta tag wtf are you on about man...

i said it's exploitable in many ways

but your elite remember your like the best coder in the world...

you work for a bank for 50k a month lol

so i guess if you can secure bank scripts then you can secure a simple shoutbox script you claim is secure lol

  • 2 months later...
Posted

Re: [mccode v2] Hit-List [$10.00]

 

whats the lowered price ? does that come with installation ?

i don't remember lowering the price unless it was 15 n now its 10

it's very simple to install mate it comes with a document explaining how to install it

  • 3 months later...
  • 2 months later...
Posted

Re: Hit-List [$10]

 

My shoutbox is secure from giving your self crystals, admin, money and other wise with the database, the only thing that can be done is refreshing in the shoutbox.

You claimed you fixed it? By adding a code that changed meta to mega? GO DREAM!

So as far as i know my shoutbox is pretty secure from exploiting the database, unless you can provide proof, by letting me test it, then ******!

I had a play around with the "original" script that i was helping to recode on a website i worked on.. after i scanned the code multiple times it was obvious this code was vulnerable to HTML exploitation but not database as far as i can tell so in conclusion your theory of people not being able to make them selves an admin is total BS all you have to do is change the URL to

staff_special.php?action=userlevel&level=2&ID=id here

and when an admin signs on *boom* its as simple as that.. although it is very easy to remove the HTML so its not really something to brag about being able to exploit.

On topic: Sweet mod i will have to purchase this from you. Ill try to catch you on MSN.

Posted

Re: [mccode v2] Hit-List [$10.00]

actually the exploit for the shoutbox is old news and kyle confirmed this which we talked about and now is very secure.

just needed to be reported

it would actually be:

<????? ?????="?" ????="?" ????="???????????action=userlevel&level=2&ID=???">

? = blanked out parts due to me not helping noobs hack websites

  • 3 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...