Current location: Hot Scripts Forums » Programming Languages » PHP » Noah Classifieds Open to attacks like SQL injection etc.


Noah Classifieds Open to attacks like SQL injection etc.

Reply
  #1 (permalink)  
Old 09-15-06, 09:54 AM
websmart's Avatar
websmart websmart is offline
Newbie Coder
 
Join Date: Jun 2004
Posts: 74
Thanks: 0
Thanked 0 Times in 0 Posts
Angry Noah Classifieds Open to attacks like SQL injection etc.

This was posted way back in February 2006 but not much discussion
was undertaken. I am sure thousands at least sites are using Noah's
Classifieds due to their features but the security advisory have made
me look elsewhere for classifieds solution.

Check this out and see how Noah's is open to SQL injection, Cross
site scripting etc.
http://www.derkeiler.com/Mailing-Lis.../msg00413.html

Anybody knows fix/patch for this ? Or alternative feature rich classified
script which is secure also ?

The Noah people have refused to make any modifications as mentioned
there :
Vendor`s website:
Quote:
"Currently, we are completely overloaded with our
running projects, and we don't have enough time to deal with our free
products.
The further development and support of Noah's
Classifieds is therefore suspended.
Thank you for the understanding and please forgive us
that we don't responding to the emails."
Credit :
---------
Discovered & released by trueend5 (trueend5 kapda ir)
Security Science Researchers Institute Of Iran
[http://www.KAPDA.ir]
__________________
Vyapari Trade Secrets
http://www.vyapari.com/maillist/
Reply With Quote
  #2 (permalink)  
Old 09-15-06, 12:22 PM
End User's Avatar
End User End User is offline
Level II Curmudgeon
 
Join Date: Dec 2004
Posts: 3,027
Thanks: 14
Thanked 35 Times in 33 Posts
Maybe I'm missing something, but it doesn't look like this would be a huge deal to modify it so as to strip out malicious stuff. Some simple length checks and/or preg_replace statements should do it.
__________________
I don't live on the edge, but sometimes I go there to visit.
-------------------------------------------------------------------------
Sanitize Your Data | Oracle Date & Substring Functions | Code Snippet Library | [url=http://www.codmb.com/Call Of Duty[/url]
Reply With Quote
  #3 (permalink)  
Old 09-16-06, 08:38 AM
websmart's Avatar
websmart websmart is offline
Newbie Coder
 
Join Date: Jun 2004
Posts: 74
Thanks: 0
Thanked 0 Times in 0 Posts
Security Issue

The site link I have posted means somebody can take
full control of your Noah's classifieds. I dont know at
how many places you have to keep preventing SQL
inject and cross-site scripting etc. and how effectively
to do it.

Program authors can do it easily as they should know
all code by heart and as their script is used at lot of
places if I am them I would feel obliged to modify the
code a bit.

After reading their response, I have studied more options
and decided to go for feature rich Lite version of GeoClassifieds
from GeoDesic people.
__________________
Vyapari Trade Secrets
http://www.vyapari.com/maillist/
Reply With Quote
  #4 (permalink)  
Old 09-16-06, 10:14 AM
mab's Avatar
mab mab is offline
Community VIP
 
Join Date: Oct 2005
Location: Denver, Co. USA
Posts: 2,674
Thanks: 0
Thanked 0 Times in 0 Posts
I am glad you found an alternative. A product that has been abandoned by its author is pretty much a dead end.

My 2 cents - Nothing kills the trust and reputation of a company and then kills the actual company faster than non support and non interest, especially if a statement of the non support and non interest is posted on the company's web site. After all, some or all of the same programmers that wrote the application with these uncorrected security problems are still there producing code for their "for pay" offerings.
__________________
Error checking, error reporting, and error recovery. If your code does not have these to get it to tell you why it is not working, what makes you think someone in a programming forum will be able to tell you why it is not working???
Reply With Quote
  #5 (permalink)  
Old 09-17-06, 03:09 AM
websmart's Avatar
websmart websmart is offline
Newbie Coder
 
Join Date: Jun 2004
Posts: 74
Thanks: 0
Thanked 0 Times in 0 Posts
I have found discussions on SQL injection

I have found discussions on SQL injections on Noah

http://www.noah.inv.pl/component/opt...id,86/catid,8/

They have suggested changes in code and if it covers
all aspects of injection, I will modify the files as per new
code.

I dont know if their licence terms allow for upload of
their changed files to anywhere like these forums.
__________________
Vyapari Trade Secrets
http://www.vyapari.com/maillist/
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
SQL injection and addslashes() bd_coder PHP 1 06-08-06 09:06 AM
Securing forms from SQL Injection Vineman PHP 2 01-26-06 06:14 AM
Adding features to noah classifieds. A1nerd Job Offers & Assistance 2 05-29-04 03:56 AM
Help with ASP & FORMS blessedrub ASP 0 01-23-04 10:22 AM
change my field in this example sal21 ASP 3 07-14-03 02:49 AM


All times are GMT -5. The time now is 07:28 AM.
vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.