SpellingCow.com Forum Index SpellingCow.com
Improving forum spelling since... well not very long
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister   ProfileProfile   Log in to check your PM'sLog in to check your PM's   Log inLog in 
Forums | Home

[fixed - sql injection!!] uh oh

 
Post new topic   This topic is locked: you cannot edit posts or make replies.    SpellingCow.com Forum Index -> Bug Tracker
View previous topic :: View next topic  
Author Message
Pickled_Weasel666



Joined: 28 May 2004
Posts: 104
Location: Oklahoma

PostPosted: Fri Jul 02, 2004 11:09 am    Post subject: [fixed - sql injection!!] uh oh Reply with quote

Error in obtaining dictionary words

DEBUG MODE

SQL Error : 1064 You have an error in your SQL syntax near 'll'' at line 3

SELECT * FROM phpbb_dictionary_words WHERE word = 'ya'll'

Line : 335
File : /usr/local/www/data-dist/spell/public_html/phpBB2/spell.php

got that when trying to add "ya'll" to the dictionary... I guess it doesn't like hick language Embarassed
_________________
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Pickled_Weasel666



Joined: 28 May 2004
Posts: 104
Location: Oklahoma

PostPosted: Fri Jul 02, 2004 11:46 am    Post subject: Reply with quote

Error in obtaining dictionary words

DEBUG MODE

SQL Error : 1064 You have an error in your SQL syntax near 's'' at line 3

SELECT * FROM phpbb_dictionary_words WHERE word = 'Mine's'

Line : 335
File : /usr/local/www/data-dist/spell/public_html/phpBB2/spell.php


As I originally feared, it doesn't like apostrophes.
_________________
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
nuttzy99
Site Admin


Joined: 23 May 2004
Posts: 1068

PostPosted: Fri Jul 02, 2004 8:48 pm    Post subject: Reply with quote

Fixed!!!! Damn, do you have any idea how big a find that is!?! Yes it breaks, but it is also a glaring security whole. Via a technique called SQL injection, it could have been possible to do anything from attaining password hashes to even deleting the entire DB!

Good find... gold star for you Wink

-Nuttzy Cool
_________________
<?php echo "something wicked awesome for my sig"; ?>
Back to top
View user's profile Send private message
GPHemsley



Joined: 27 May 2004
Posts: 139
Location: Long Beach, NY

PostPosted: Fri Jul 02, 2004 11:30 pm    Post subject: Reply with quote

nuttzy99 wrote:
even deleting the entire DB!

Shocked You gave the SpellingCow database user permission to delete databases? Shocked
_________________
Gordon P. Hemsley
A Link to the PastCMSformE
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address
nuttzy99
Site Admin


Joined: 23 May 2004
Posts: 1068

PostPosted: Fri Jul 02, 2004 11:41 pm    Post subject: Reply with quote

GPHemsley wrote:
nuttzy99 wrote:
even deleting the entire DB!

Shocked You gave the SpellingCow database user permission to delete databases? Shocked
They could certainly empty all the tables which is the same thing in my opinion. No way of getting around that!

-Nuttzy Cool
_________________
<?php echo "something wicked awesome for my sig"; ?>
Back to top
View user's profile Send private message
ZoliveR



Joined: 27 May 2004
Posts: 80

PostPosted: Sat Jul 03, 2004 6:18 pm    Post subject: Reply with quote

Happy to see that problems can be easily and quickly fixed Wink
Nuttzy you rock Wink
_________________
I'm the belgian chocolate eater Wink
Back to top
View user's profile Send private message MSN Messenger
nuttzy99
Site Admin


Joined: 23 May 2004
Posts: 1068

PostPosted: Tue Jul 27, 2004 10:44 am    Post subject: Reply with quote

Thanks Z Wink

Locking since this one is done and conversation is long over.

-Nuttzy Cool
_________________
<?php echo "something wicked awesome for my sig"; ?>
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    SpellingCow.com Forum Index -> Bug Tracker All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group :: Spelling by SpellingCow.

SpellingCow.com Privacy Policy | blueGray theme by Nuttzy

Sponsors:
Identity Theft Protection - Compare identity theft protection services
Structured Settlements - cash for structured settlements, sell annuity, lottery winnings, and more.
Barcode Scanner Manufacturer - taiwan manufacturer of scanners, swipe card reader, serial-ethernet converter, cash drawer, and other pos devices.
Advice, help & demonstrations for sign makers - Europe's leading sign makers website
Tattoo - we are a group of tattoo enthusiasts