Current location: Hot Scripts Forums » Programming Languages » PHP » Is it possible?


Is it possible?

Reply
  #1 (permalink)  
Old 08-30-04, 03:45 AM
eddyvlad eddyvlad is offline
Wannabe Coder
 
Join Date: Sep 2003
Location: In The Bloody Pits Of Hell
Posts: 160
Thanks: 2
Thanked 0 Times in 0 Posts
Is it possible?

Is it possible to extract or get unknown variable from an online php site?
Example, there is this http://www.somesite.com/info.php
I don't have any idea of the variable names in that file but is it possible to extract them?
__________________
Mr. Brown Eyes
Reply With Quote
  #2 (permalink)  
Old 08-30-04, 03:56 AM
eq1987 eq1987 is offline
Wannabe Coder
 
Join Date: Dec 2003
Posts: 216
Thanks: 0
Thanked 0 Times in 0 Posts
I can't say 100% sure, but PHP is very secure. Getting a variable would be in a sense, "hacking". Javascript might be able to do it. Not get the actual variable, but the same results. Since I don't know what your trying to accomplish, I cant say for sure.

Ex. of what i mean:
I have recent forum posts on my site.I could have used PHP & MySQL Select, but I was able to use JS. I of course didn't write the JS, it is a mod. (i don't know Javascript)

If it is possible, hopefully someone will post.
Reply With Quote
  #3 (permalink)  
Old 08-30-04, 04:51 AM
Andy1984's Avatar
Andy1984 Andy1984 is offline
Newbie Coder
 
Join Date: Jul 2004
Posts: 89
Thanks: 0
Thanked 0 Times in 0 Posts
viewing someone elses php files would be a security risk. like you could get the username/password to a db or any other sensitive data. also what if someone is trying to make money from selling there php scripts and instead someone decides to have a look at there code. from what ive seen i doubt its possible. or atleast not very easy todo. you would probably have to hack and download the actual php document and that would be bad

Last edited by Andy1984; 08-30-04 at 04:53 AM.
Reply With Quote
  #4 (permalink)  
Old 08-30-04, 01:24 PM
eddyvlad eddyvlad is offline
Wannabe Coder
 
Join Date: Sep 2003
Location: In The Bloody Pits Of Hell
Posts: 160
Thanks: 2
Thanked 0 Times in 0 Posts
Well.. in order to create a secure php script, you gotta know the security risk rite?

The actual reason I ask was because I am in this online profile/community thing and I tried to use html on my nick, so it stand out from the rest.. Say... a red colour nick. I bypass the javascript validation by creating my own external form and post it to the original php. But now the admin detected my nick and now create the validation in php. If only I can find out what's going on in the script... hmmm....
__________________
Mr. Brown Eyes
Reply With Quote
  #5 (permalink)  
Old 08-30-04, 01:39 PM
eq1987 eq1987 is offline
Wannabe Coder
 
Join Date: Dec 2003
Posts: 216
Thanks: 0
Thanked 0 Times in 0 Posts
If you want a red font, and the owner doesn't stip tags, you could just type:
<font color="red">My nickname</font>
Reply With Quote
  #6 (permalink)  
Old 08-30-04, 02:38 PM
eddyvlad eddyvlad is offline
Wannabe Coder
 
Join Date: Sep 2003
Location: In The Bloody Pits Of Hell
Posts: 160
Thanks: 2
Thanked 0 Times in 0 Posts
Quote:
Originally Posted by eq1987
If you want a red font, and the owner doesn't stip tags, you could just type:
<font color="red">My nickname</font>
Dude.. I did that before. Now they're aware of it. That's why I'm posting this.
__________________
Mr. Brown Eyes
Reply With Quote
  #7 (permalink)  
Old 08-30-04, 09:19 PM
blaw's Avatar
blaw blaw is offline
Junior Code Guru
 
Join Date: Dec 2003
Location: Vancouver, BC, Canada
Posts: 550
Thanks: 0
Thanked 0 Times in 0 Posts
Hello,

When certain conditions meet, it's possible to do what you want to do, but it is difficult to meet those conditions or PHP would have been dead by now.

Your post sounds a bit like asking how to break into a bank silently, unnoticed so that you can pick up your cell phone that you had forgotten on the desk during the daytime.

The best advice I can give you is ask the administrator of the community to implement such features.

HTH.
__________________
Blavv =|
Reply With Quote
  #8 (permalink)  
Old 09-01-04, 04:46 PM
Eclipse's Avatar
Eclipse Eclipse is offline
Coding Addict
 
Join Date: May 2004
Location: Long Island, New York
Posts: 356
Thanks: 0
Thanked 0 Times in 0 Posts
I don't mean to sound like an assh0le but your that much of an attention-wh0re?

Edit: I needed to replace the "o"s with "0"s due to the word filter not because I use "leet"
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT -5. The time now is 04:24 AM.
vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.