Firefox Breed Posted October 16, 2008 Share Posted October 16, 2008 Thanks to the wonderful things known as PHP/MYSQL there is a new way if submiting stuff to Curia.Register here: http://www.ordoimperialis.com/firefox/The reg pass is "snowwolf"You will see on the menu there is "CIR" and that is the form. Now you can pass them in game using note cards still but we recommend you use this new form. Where will be a error message when you first register but go to the Rank/Branch tab, fill it out and it will go away.If any questions please post them here. Quote Link to comment Share on other sites More sharing options...
Nakita Posted October 17, 2008 Share Posted October 17, 2008 Moy Loon wrote:I give you an F, You've failed at producing even a moderately safe application, I've been able to SQL inject at your LOGIN PAGE. If I were someone trying to cause harm, you would have nothing left in your tables, aswell as new files on the server to allow access to everything on it. (Think access to the forum files, (learning of MYSQL password, everyones password/username/email all open to them, and everything else that is hosted on this site, and all it's information, a very scary scenario).You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ');",`.~lol'' at line 1Nice to see you being helpful as always. Quote Link to comment Share on other sites More sharing options...
Trevor Russell Posted October 17, 2008 Share Posted October 17, 2008 Moy Loon wrote:I give you an F, You've failed at producing even a moderately safe application, I've been able to SQL inject at your LOGIN PAGE. If I were someone trying to cause harm, you would have nothing left in your tables, aswell as new files on the server to allow access to everything on it. (Think access to the forum files, (learning of MYSQL password, everyones password/username/email all open to them, and everything else that is hosted on this site, and all it's information, a very scary scenario).You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ');",`.~lol'' at line 1Hows about doing something to fix it? Quote Link to comment Share on other sites More sharing options...
Streak Bender Posted October 17, 2008 Share Posted October 17, 2008 Moy Loon wrote:I give you an F, You've failed at producing even a moderately safe application, I've been able to SQL inject at your LOGIN PAGE. If I were someone trying to cause harm, you would have nothing left in your tables, aswell as new files on the server to allow access to everything on it. (Think access to the forum files, (learning of MYSQL password, everyones password/username/email all open to them, and everything else that is hosted on this site, and all it's information, a very scary scenario).You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ');",`.~lol'' at line 1Lay off, he's been working hard on this, and I for one deeply appreciate it. Don't be a jerk. Quote Link to comment Share on other sites More sharing options...
Firefox Breed Posted October 17, 2008 Author Share Posted October 17, 2008 Moy Loon wrote:I give you an F, You've failed at producing even a moderately safe application, I've been able to SQL inject at your LOGIN PAGE. If I were someone trying to cause harm, you would have nothing left in your tables, aswell as new files on the server to allow access to everything on it. (Think access to the forum files, (learning of MYSQL password, everyones password/username/email all open to them, and everything else that is hosted on this site, and all it's information, a very scary scenario).You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ');",`.~lol'' at line 1Give me some references on how to secure it and I shall fix it. Quote Link to comment Share on other sites More sharing options...
Inoue Katsu Posted October 17, 2008 Share Posted October 17, 2008 php has a mysql escape command .. which i think i even mentioned at some point to you :ogoogle it ! Quote Link to comment Share on other sites More sharing options...
Cygna Posted October 17, 2008 Share Posted October 17, 2008 Moy Loon wrote:I give you an F, You've failed at producing even a moderately safe application, I've been able to SQL inject at your LOGIN PAGE. If I were someone trying to cause harm, you would have nothing left in your tables, aswell as new files on the server to allow access to everything on it. (Think access to the forum files, (learning of MYSQL password, everyones password/username/email all open to them, and everything else that is hosted on this site, and all it's information, a very scary scenario).You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ');",`.~lol'' at line 1Thanks for the concern Moy. I'm sure with the information you've provided, Firefox can tighten his security. About the rest of the server:Echelon on security: Quote Link to comment Share on other sites More sharing options...
Phillip Hultcrantz Posted October 17, 2008 Share Posted October 17, 2008 Tsume Xiao wrote:Since no one seems to have said this....Awesome FireFox.. I'm sure Kitsy and the other Curia staff will be glad not to have nearly as many notecards flooding them :DYeah but now they will be getting emails/online forms to deal with :D Quote Link to comment Share on other sites More sharing options...
Aryte Posted October 17, 2008 Share Posted October 17, 2008 Thank you Firefox, for being trapped in Egypt and doing stuff like this while you're bored (not defending your station) in a guard tower.And thank you Moy, albeit crudely, for pointing out security problems. Quote Link to comment Share on other sites More sharing options...
Firefox Breed Posted October 17, 2008 Author Share Posted October 17, 2008 Try it now moy Quote Link to comment Share on other sites More sharing options...
Justice Capalini Posted October 17, 2008 Share Posted October 17, 2008 Thank you Firefox this will help alot. Quote Link to comment Share on other sites More sharing options...
Sekonda Huet Posted October 18, 2008 Share Posted October 18, 2008 o.o? Quote Link to comment Share on other sites More sharing options...