vulnerable ?

Dr. GBooky is here to help you with your guestbook problems ...
Post Reply
vincenttor
Posts: 7
Joined: Tue Aug 04, 2009 9:15 am

vulnerable ?

Post by vincenttor »

i know this is not the right way to post it
but i was checking my statistics

and found someone came on my site by this searching method

inurl:"gbook.php?a=sign" site".com

12 Aug, 09:33:49

Oekraïne Oekraïne

102.114.120.77.colo.static.dc.volia.com

1

Linux Linux i686

Firefox Firefox 3.5

www.google.com.ua

http://www.google.com.ua/search?q=inurl ... t=200&sa=N

could there be something vulnerable for script kiddy's or something in the guestbook ?
DC
Posts: 138
Joined: Sun Dec 09, 2007 9:28 am

Post by DC »

I am not the dev but I can tell you this I have been using JunkYard Scripts since the get go and they are usually very solid and tight against hacks as you mention. so I would highly doubt that Klem would allow such hack points to exist.

But im sure he will post next and let you know.
Thats just my 2 cents on what I know, as I have been using and tweaking them forever.

DC
To Code Or Not To Code That Is The Question?

Was my post of any help to you? if so please do [url=http://www.clickcraft.net/slice_donations.php][b]Buy Me A Slice[/b][/url] ...
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Anyone can attempt with any URL

gbook.php?page=xxx.com
gbook.php?page=SOME_MAILCIOUS CODE

But this doesn't mean it's a vulnerability because GBook validated input parameters and $page defaults to 1 if an invalid page is entered (or any other variable for that matter).

So this means some script kiddie is trying, but it's not a vulnerability as GBook checks the code before executing it.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
vincenttor
Posts: 7
Joined: Tue Aug 04, 2009 9:15 am

Post by vincenttor »

no i dont doubt that, but thought maybe good to let you know if there is something wrong
did not knew that

its a super guestbook no problems @ all with it
Post Reply