Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Penetration Testing


ghost's Avatar
0 0

Hi,

I've been coding my personal blog and have come to the point of releasing it to the public. I am now looking for people to try and hack the site. Anyone interested post here


mozzer

URL: PHP-GSY


Mr_Cheese's Avatar
0 1

if you want it professionally penetration tested contact me and i can organise a very reasonable price. full reports are given etc etc


ghost's Avatar
0 0

I meant it more as a challenge for the HBH users, but if I ever do need something like that done I'll keep you in mind


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

"Copywrite" lolz :p


ghost's Avatar
0 0

Meh, someone has already pointed that out to me at school. Forgot to change it

Thanks system :):)


ghost's Avatar
0 0

Upon careful review of……1 minute, i have found…. dramatic sequence

Incorrect is spelt incorrect!

buahahahahah…:ninja:


ghost's Avatar
0 0

Where? Post a comment on the site so I can find it. (NB, you don't have to use a real email)

[EDIT=1]

  • Slaps head [/EDIT]

ghost's Avatar
0 0

so this blog uses readblog.php script to read blogs. so if i select some nonexistant id or i just dont sellect it at all(exmp: http://phpgsy.com/readblog.php?id=99) i can add comments on a empty blog?! Its not vuln, but still it should be fixed :) cya


ghost's Avatar
0 0

Well spotted, I never noticed that, thank you


ghost's Avatar
0 0

again, a funny bug… in admin.php if u add argument comment with some value it would add that value bellow the 'submit' button. exmp: admin.php?comment=roflmao would add 'roflmao' bellow the submit button


AldarHawk's Avatar
The Manager
0 0

Most likely not anything big but if you post a comment that is blank with all the other fields blank it still posts. Might want to add a if statement to avoid null floods.


ghost's Avatar
0 0

Well I tried some common xss'ploits and they didn't work.

Stupid html entities :X

:) - nice site


ghost's Avatar
0 0

@Aldar, yes I am going to be improving the comments to stop null and repeat comments


ghost's Avatar
0 0

only wrote: again, a funny bug… in admin.php if u add argument comment with some value it would add that value bellow the 'submit' button. exmp: admin.php?comment=roflmao would add 'roflmao' bellow the submit button

I haven't found that, I dunno if thats just you. Anyone else seen it?


ghost's Avatar
0 0

only wrote: again, a funny bug… in admin.php if u add argument comment with some value it would add that value bellow the 'submit' button. exmp: admin.php?comment=roflmao would add 'roflmao' bellow the submit button

mozzer wrote: I haven't found that, I dunno if thats just you. Anyone else seen it?

Doesn't work for me. "only", what browser are you using?


ghost's Avatar
0 0

my mistake its 'content' not 'comment' :)

i use firefox btw

screenshot:


ghost's Avatar
0 0

that bug is now officially confirmed, works here too. Oh btw "only", please resize or remove that img pleeeaaase :P ITS SO HUGE xD


ghost's Avatar
0 0

done, sorry about that one :)


ghost's Avatar
0 0

I know it is a problem. It's the host's damn register_globals


ghost's Avatar
0 0

ok i have an idea. in the admin.php maybe u can change the author by a javainj or something and then try to login? its just a proposition i dunno if it works, and im kinda busy lately so i have no time to try out. cheers


ghost's Avatar
0 0

No you can't change the author and log in like that.


ghost's Avatar
0 0

BBCode is now up. And I expect there are a few exploits there already


ghost's Avatar
0 0

is it just me or something is fucked up, i cant post comment…


ghost's Avatar
0 0

No, it must be just you, unless you are neglecting a field or something