![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
possible NATS exploit?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Jan 2005
Posts: 8,920
|
I guess that the script connects to a nats site and sponsors get it down for too many requests.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Apr 2006
Location: usa
Posts: 508
|
I have n o idea.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Sounds more like a more serious problem at first sight
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
nothing directly related to nats. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
What about the other programs that also do not seem to work ?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jan 2005
Posts: 8,920
|
Anyway its getting popular so everybody will start finding bugs for it soon.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
Confirmed User
Join Date: Jan 2005
Posts: 8,920
|
Quote:
No, but happens with everything... phpbb... vbulletin... windows... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
...
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
|
is this for real?
__________________
... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Need Designs? 312352846
Industry Role:
Join Date: Dec 2004
Location: Somewhere
Posts: 11,687
|
some nats programs are ok
__________________
NEED DESIGNS?!? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Confirmed User
Join Date: Jun 2005
Location: Irvine, CA
Posts: 2,442
|
Quote:
There are Zend decoders now, though.
__________________
254342256
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Confirmed User
Join Date: Jan 2005
Posts: 8,920
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Jul 2006
Location: SplitInfinity.com
Posts: 3,637
|
Just a matter of time i think.. all adult-cms had/have bugs..
![]() mpa,sitdepth and so on ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Jul 2006
Location: SplitInfinity.com
Posts: 3,637
|
There wasnt a public advisory as far as i know but i said it here allready http://www.gofuckyourself.com/showthread.php?t=629368
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
Thx for the info
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
This is not a NATS bug, its neither a NATS exploit.
People that do not understand errors should not throw around words like "exploit"... what other programs do not work right now? I only know of this one problem with panchodog. The error with panchodog is a mysql problem, not a NATS problem. Just because NATS is so nice and actually produces intelligent error displays for the client does not mean its a damn NATS problem or exploit!
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Doin fine
Industry Role:
Join Date: Oct 2005
Posts: 24,983
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | ||
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
Quote:
|
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Quote:
Lol.. ok, if ya say so... What would be intelligent? "Sorry, but there is a problem, please come back later."??? So the client has to sit there and figure out for hours what the issue actually is? The page tells you EXACTLY what the problem is, thats the whole point of an error. Just because YOU do not understand it does not mean its not a correct error.
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
haha listen, now you got me mad, you're a fucking idiot, I know better than you what that means You shouldn't disclose informations to the public moron A message like "A mysql error was found" would've been more intelligent than telling all the world where nats is installed so it can be abused when a bug is found. That shit is called "path disclosure" look it up genius. Also, You don't have to display errors on the site for YOUR customer to see it. Those can be logged separately. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Your error just told me:
the panchodog server is running freebsd theres a table called accounts in nats nats is installed in /usr/home/natsinstall panchodog is running version 3.0.29 Quote:
DO YOU REALLY NEED TO GIVE THAT INFO TO THE PUBLIC YOU are so fucking intelligent and so are your errors |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Sorry I made you mad, lol...
oppinions, oppinions.. everyone and their mother has one... We create the errors in this way so the clients notice them, we know our clients... The location disclosure of NATS itself is also no problem because in now-a-days exploits the path can be retreived anyway, its not so hard ya know, people that use exploits will find it fast anyway (in case they even NEED it, which is not even the case)... There is a reason why not even apache has a problem with disclosing full paths to websites, nor does PHP on standard php errors... We tried many different error displays in the past, we also had it turned off totally for some time and only did logging, we had too many clients get problems because of it and this way simply fixes things faster (98% of the time)... The errors do not disclose information that could not be retreived in many other ways if you want to exploit someone...
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Quote:
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 | |
So Fucking Banned
Join Date: Oct 2003
Location: icq: 121189
Posts: 18,889
|
Quote:
Dude, that's not exactly difficult to figure out, even without an error message. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 | ||
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
I see you ignored my advice.
Quote:
Quote:
I don't want to think how much shit can be fetched from your script. You are supposed to take security seriously and not this fuck it attitude. Just because it can happen in other ways doesn't mean your script has to allow it. |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
I'll give you one day to show me that data without using nats. if not you'll have to build 100 galleries for epictrash |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
I did not call our clients idiots, far from it.. all I said is that we know our clients well, and we know what they want and ask from us ;)
The errors are created like this for a reason, I told you that plenty of times, if you do not understand or agree, thats not my problem, its yours... The information disclosed in no way is a problem, it only helps us and the client, and thats what it is there for... BTW, I just looked at axscripts.com, a friendly advice... you might want to reconsider posting here...
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Quote:
And hey, if you know of bugs in NATS (guessing that is what you mean by "what pos your script is"), please do tell! I'd love to know them so we can fix them (in case we have not already in our latest version)
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | |
So Fucking Banned
Join Date: Oct 2003
Location: icq: 121189
Posts: 18,889
|
Quote:
Because I have a working knowledge of php and sql. Considering what you do, I'm shocked as hell you're making such a big deal out of this. Every fucking script I know of displays at least SOME path info in error messages when there are DB issues. There are also 50 million ways to find that info out even without an error. Your motivations in this are more than a little suspect. You don't dictate ANYTHING to me, btw. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 |
Confirmed User
Join Date: Mar 2006
Location: Illinois
Posts: 9,483
|
random bump
__________________
![]() BigCocks.com - MatureWomen.com - Tranny.com - DrunkGirls.com - TeenGirls.com - MonsterCock.com and many more... Click here to see them all! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
So Fucking Banned
Join Date: Oct 2003
Location: icq: 121189
Posts: 18,889
|
PS, on that lame little support forum for that shitty little trade script you have, there are several posts discussing errors of a similiar nature, AND displaying similiar information. IE. paths, etc.
Does that mean that POS you spam has an exploit? LMA0 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 | ||
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
about servers and when you tell me I dont understand a mysql error yea it gets me mad Quote:
but thanks, I've wasted enough time on it. |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
It just give too much information and I don't call that an "intelligent error" |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
I coded it in two hours but it wont give away any substantial info if lets say it would be hacked. Can nats say the same if someone hack them ? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Quote:
and I'm not cocky, I'm just good at what I do.. well.. and I'm german, so my english might not be perfect...
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#46 | |
So Fucking Banned
Join Date: Oct 2003
Location: icq: 121189
Posts: 18,889
|
Quote:
Dude, seriously. How is it NOT intelligent? NATS has found a problem DB Error: Can't open file: 'accounts.MYI'. (errno: 145) /usr/home/natsinstall/nats/includes/database.php:430 That gives you the db name, error code, file thats making the call and on what LINE of code the call is being made from. I just don't get you. lol I don't see how that could be more clear. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#47 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Quote:
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#48 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
If you are so good at what you do , do you know how "least privileges" principle works ? And if yes, why don't you apply it ? Why nats gives access to the entire database to the user thats supposed to fetch only user and passwords ? (and I have nothing with too much media, this is between you and me cause you started the shit not your company) |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#49 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
I dont need to hide my code behind encoders |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#50 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 3,108
|
Quote:
Seriously, people in a glass house should not throw with stones, you are looking stupid here. Also, NATS has no single user that only fetches user and password... if you mean SPARTA setups with NATS, we actually tell our clients specifically which tables we need select and which we need update/insert privileges on...
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right." - Charlie Munger |
|
![]() |
![]() ![]() ![]() ![]() ![]() |