1
Hacking and Security / Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
« on: May 04, 2015, 10:06:45 PM »
Go ahead, I'm here to piss people off, it's amusing. It's called trolling.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
And who the hell would ever let reaver run its full course nowadays? Oh yeah, dumb fucks that don't have a clue what they are talking about.
Okay okay okay okay. Calm down ladies.
@HTTP, why do you like this one better? Security concerns or design/features?
@DeepCopy, I appreciate the trust you have in me, but even I can make mistakes. And there are some valid points here. Closed source and security has rarely ended well. But 'alpha' is not closed source, there have been many eyes on it and there will continue to be. We might even make it open source ish at some point. But I dont think it is a good idea to make it public open source just yet. It is still very much unfinished and unpolished.
PDO does take care of most database related vulnerabilities, but not all. There are queries that needs to be done in a different way than PDO wants, but thing is I am very much aware of these, and they are few.
As far as XSS goes I am fairly sure we are up to date.
DDoS has nothing to do with software. Unless you are speaking of a software DoS flaw, which there have been a few of in alpha but most of them have been corrected, and future ones will be fixed swiftly if discovered.
You are all more than welcome to go bug hunting as long as you report what you find I would very much appreciate in fact.
There has been some time since the alpha GIT was updated because of lack of interest, from me and others. Do tell if you are interested and we'll see what we can do about that.
EDIT: Ps: I just realized this reply might be slightly offending. That was not my intention. <3
As far as Security is concerned, a DDoS can take a site down, but does not get them on the box to take over the site or dump a database. So Security wise it's not an issue. DDoS will plague any site, regardless of the Security of the code.
Looks good ande
@HTTP
You have no idea how much improvement alpha has over SMF. the biggest being a custom forum software which will make it very difficult for people to attack. For example, skiddy gets 0day SMF exploit and pwns EZ, with alpha, only evilzone is using it. No vBulletin, no SMF, no phpBB, no etc. This already makes it more secure by leaps and bounds.
Also if problems and bugs arise they can be addressed by the creators of alpha and not rely on some hack patches. Furthermore additional services and APIs can enable for beautiful uniform integrated parts of evilzone (ie services that used to have a link in the previous alpha)
Change isn't always accepted, however I believe alpha is going to be one of the best things that has happened to EvilZone in a LONG time.
I would love to see a full CMS for other sites to use xD
Link?