Website Critiques
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsWeb DesignWebsite Critiques

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old September 26th, 2003, 10:47 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
http://www.betachat.com/devshed.html

Got a challenge for all of you if you're up to it! Website is..
http://www.betachat.com/devshed.html

Main thing is, see if you can log into the chatroom with no username, blank.. Next, see if you can log into the chatroom with the username "Rick".. Then just see if you can spot any security holes.. Written in python. Let me know what you come up with.
__________________
"I haven't failed, I've found 10,000 ways that won't work."
- Thomas Edison

-=Rick=-

Chat Refinance Loans

Reply With Quote
  #2  
Old September 28th, 2003, 03:10 AM
Milo's Avatar
Milo Milo is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2003
Location: Minneapolis, MN
Posts: 14 Milo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 m 25 sec
Reputation Power: 0
can't login with "rick"..name is reserved.

can't login with "" ..."Invalid username."

can't login with anything else..."name is already in use"

don't know what else you would like to try.

Reply With Quote
  #3  
Old September 28th, 2003, 09:09 AM
lisajill lisajill is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 152 lisajill User rank is Private First Class (20 - 50 Reputation Level)lisajill User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 5
Send a message via ICQ to lisajill Send a message via AIM to lisajill Send a message via Yahoo to lisajill
only tried twice...

in firebird 0.6.1 on pc the first time it did something then came back to the first page.

the second time it said this:

JavaScript Error reported...
__________________
Lisa
distant, early morning

Reply With Quote
  #4  
Old September 29th, 2003, 10:11 AM
Sepodati's Avatar
Sepodati Sepodati is offline
Banned
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Dec 1999
Location: Afghanistan
Posts: 14,378 Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)Sepodati User rank is General 12nd Grade (Above 100000 Reputation Level)  Folding Points: 70305 Folding Title: Intermediate FolderFolding Points: 70305 Folding Title: Intermediate FolderFolding Points: 70305 Folding Title: Intermediate FolderFolding Points: 70305 Folding Title: Intermediate Folder
Time spent in forums: 2 Months 3 Weeks 6 Days 22 h 26 m 46 sec
Reputation Power: 1784
Send a message via ICQ to Sepodati Send a message via Yahoo to Sepodati
The Fort Gordon Policy clearly states that access to this site is prohibited.

For further information please read Fort Gordon Garrison Policy Letter #17.


---John Holmes...

Reply With Quote
  #5  
Old September 29th, 2003, 01:31 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by Milo
can't login with "rick"..name is reserved.

can't login with "" ..."Invalid username."

can't login with anything else..."name is already in use"

don't know what else you would like to try.


I wanted to see if anyone could "crack" passed my reserved name.

Empty form will give that error, wanted to see if anyone found any holes in it to be able to login without a username, for instance alt+0160..

Name is already in use is strange..

Thanks for lookin'

Reply With Quote
  #6  
Old September 29th, 2003, 01:56 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by lisajill
only tried twice...

in firebird 0.6.1 on pc the first time it did something then came back to the first page.

the second time it said this:

JavaScript Error reported...


When you press enter, or click submit, a new window will appear, you may want to try pressing "Ctrl" when hitting enter, or pressing submit.

Thanks for tryin'.

Reply With Quote
  #7  
Old September 29th, 2003, 01:59 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by Sepodati
The Fort Gordon Policy clearly states that access to this site is prohibited.

For further information please read Fort Gordon Garrison Policy Letter #17.


---John Holmes...


You must be from Fort Gordon Garrison? I don't see why it's prohibited..

Thanks for tryin' anyway.

Reply With Quote
  #8  
Old November 16th, 2003, 07:25 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by Sepodati
The Fort Gordon Policy clearly states that access to this site is prohibited.

For further information please read Fort Gordon Garrison Policy Letter #17.


---John Holmes...


Sep, what's this about being prohibited?

Reply With Quote
  #9  
Old November 16th, 2003, 11:11 PM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 8 m 45 sec
Reputation Power: 27
Quote:
The requested URL /devshed.html was not found on this server.

Please contact the server administrator, rick@betachat.com and inform them of the time the error occurred, and anything you might have done that may have caused the error.

Please go back and try again.

Reply With Quote
  #10  
Old November 16th, 2003, 11:17 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by a.koepke


Oops, deleted it. It's back up now.

Reply With Quote
  #11  
Old November 16th, 2003, 11:19 PM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 8 m 45 sec
Reputation Power: 27
All it ends up doing is redirecting me to Devshed.com

What is this meant to do?

Reply With Quote
  #12  
Old November 16th, 2003, 11:22 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by a.koepke
All it ends up doing is redirecting me to Devshed.com

What is this meant to do?


Ah, I see. You have to click Chat, then immediately after, punch and hold the control key. It's a new pop up window. That's where the chat will be.

Reply With Quote
  #13  
Old November 16th, 2003, 11:40 PM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 8 m 45 sec
Reputation Power: 27
If someone has to do some crap like that to enter a chat room I think most people are not going to bother.

Why don't you come back when you have programmed things properly.

Reply With Quote
  #14  
Old November 16th, 2003, 11:44 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 6
Quote:
Originally posted by a.koepke
If someone has to do some crap like that to enter a chat room I think most people are not going to bother.

Why don't you come back when you have programmed things properly.


It is done properly. You have a popup stopper blocking the page from opening. The pop up is for a reason.

Reply With Quote
  #15  
Old November 17th, 2003, 01:12 AM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 8 m 45 sec
Reputation Power: 27
Well I have mozilla with popup blocking enabled.

Redirecting, displaying no message to the user and just expecting things to work is not doing things properly.

If you need to make it a popup you should redirect to a page with a javascript link that would say "If you do not see a popup chat window please click here" and that would then run the javascript to popup the window. Due to this being a user-initiated popup the popup blockers shouldnt block it.

Reply With Quote
Reply

Viewing: <