GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Simple linkex exploit. BEWARE. (https://gfy.com/showthread.php?t=763605)

v0id 08-27-2007 04:15 AM

Quote:

Originally Posted by fluffygrrl (Post 12993240)
Actually. The "fix" doesn't fix the problem, from what I can see. Feel free to give it a try yourself, as explained in the original post.

Not sure what you mean. Can you elaborate?

- v0id

v0id 08-27-2007 04:17 AM

Quote:

Originally Posted by fluffygrrl (Post 12993240)
Actually. The "fix" doesn't fix the problem, from what I can see. Feel free to give it a try yourself, as explained in the original post.

Not sure what you mean. Can you elaborate?
demo.linkex.dk/linkex/data/output/1001

- v0id

fluffygrrl 08-27-2007 04:25 AM

Code:

<!-- Output generated by LinkEX (+http://linkex.dk/) -->
<a href="http://lolcunts.org" title="&lt;?php echo'hi'; ?&gt;">&lt;?php echo'hi'; ?&gt;</a><br><br><a href="http://www.teensexvidz.com/" title="Teen Sex Videos">Teen Sex Videos</a><br><br>

does that help ?

cykoe6 08-27-2007 04:32 AM

So has this issue been solved or not.....

GirlsOnYou 08-27-2007 04:48 AM

Quote:

Originally Posted by fluffygrrl (Post 12993283)
Code:

<!-- Output generated by LinkEX (+http://linkex.dk/) -->
<a href="http://lolcunts.org" title="&lt;?php echo'hi'; ?&gt;">&lt;?php echo'hi'; ?&gt;</a><br><br><a href="http://www.teensexvidz.com/" title="Teen Sex Videos">Teen Sex Videos</a><br><br>

does that help ?

You do realize that &lt;?php does nothing whereas <?php does, right?
So that code you just posted cannot be harmful because < is replaced with &lt;.

You might know this and I might have missed the point of your post but I told this just in case.

potter 08-27-2007 05:14 AM

Quote:

Originally Posted by fluffygrrl (Post 12991187)
Listen blockhead. You need to comprehend a few points.

1. I don't owe you, or any dude running some script, or any dude putting up scripts for download, jack shit. The day you, or those other dudes have me on their payroll, you can raise this point again. Till then, chuck it.

1.1. I might, might mind you, out of the kindness of my heart, and because I'm such a nice fellow, given the author of the shoddy script a fix, provided he wasn't the sort of douchebag that deliberately makes his "code" hard to read. Call this a lesson in the theory of "karma's a bitch", maybe next time he releases code, he follows standards.

2. Responsibility for computer code at all times remains with the USER of such code. If you install and run some script you haven't completely read and understood, heck. Your bubblings to the contrary are really akin to the idiots wanting me to keep their children off the "dangerous internet". The internet is for grown-ups. Grown-ups are those people who understand where responsibility lies. Letting children, and you, run amok on the internet is fine, as far as I'm concerned, but their safety is not my problem.

3. Information belongs out in the open. That Bush, Cheney, and you think it's best to try and restrict the flow of information is exactly your problem, much like the belief in a flat earth and an omnipotent benevolent god is the believer's problem. If some women get butchered in China or if some shitty script has a hole in it, the public has a right to know, and you don't have a right to have an oppinon on the matter.

Bloody hell.

That was awesome...

fluffygrrl 08-27-2007 05:24 AM

Doh. I was including the wrong file.

So yes, linkex.20070827.tar.gz fixes the hole.

v0id 08-27-2007 06:25 AM

so, now everyone have to update their linex!!

KrisKross 08-27-2007 06:53 AM

Quote:

Originally Posted by LinkEX (Post 12993590)
so, now everyone have to update their linex!!

No apologies for shitty code?

teg0 08-27-2007 07:00 AM

Quote:

Originally Posted by KrisKross (Post 12993696)
No apologies for shitty code?

Windows = shitty code

cykoe6 08-27-2007 08:28 AM

Quote:

Originally Posted by KrisKross (Post 12993696)
No apologies for shitty code?

Why should he apologize when the script is free? I think it is a very useful script considering it is free and I apprecaite the quick action to fix the problem. :thumbsup

v0id 08-28-2007 04:18 AM

Quote:

Originally Posted by KrisKross (Post 12993696)
No apologies for shitty code?

I don't see why I should. As I recall you either have or are using LinkEX on your site(s), never heard any "thank you" from you?

The only thing I regret is the trouble people is going to have, since they have to update their installations, because of a stupid mistake.
There are properly many more bugs in LinkEX, but you get what you pay for, and I don't feel like apologise for every one of them. You get the script for free, and in return help me come up with ideas and report bugs. :thumbsup

- v0id

Libertine 08-28-2007 07:01 AM

Quote:

Originally Posted by LinkEX (Post 12998501)
You get the script for free, and in return help me come up with ideas and report bugs. :thumbsup

Protip: if you want ideas and bug reports, make your code readable. Hell, you could even splurge and add some comments.

Doctor Feelgood 08-28-2007 07:47 AM

does the uodate still use this path for cron to check backlinks?
my-site.com/linkex/index.php > /dev/null

v0id 08-28-2007 08:45 AM

Quote:

Originally Posted by Doctor Feelgood (Post 12999058)
does the uodate still use this path for cron to check backlinks?
my-site.com/linkex/index.php > /dev/null

Yup

Code:

/path/to/php /path/to/your/linkex/index.php[ --verbose]
will check the backlinks, use the --verbose to have it write the results to stdout

KrisKross 08-28-2007 08:50 AM

Quote:

Originally Posted by LinkEX (Post 12998501)
I don't see why I should. As I recall you either have or are using LinkEX on your site(s), never heard any "thank you" from you?

The only thing I regret is the trouble people is going to have, since they have to update their installations, because of a stupid mistake.
There are properly many more bugs in LinkEX, but you get what you pay for, and I don't feel like apologise for every one of them. You get the script for free, and in return help me come up with ideas and report bugs. :thumbsup

- v0id

I don't use your script and don't intend to.

When you release code for people to use across hundreds of sites, it's common courtesy to ensure your code is readable and not full of major security holes.

People with no scripting knowledge trust that YOU know what you're doing and that the code will be safe.

v0id 08-28-2007 09:43 AM

Quote:

Originally Posted by KrisKross (Post 12999275)
I don't use your script and don't intend to.

Sorry my bad, just thought you did based on a post like this gofuckyourself.com/showpost.php?p=12746111&postcount=8

Quote:

Originally Posted by KrisKross (Post 12999275)
When you release code for people to use across hundreds of sites, it's common courtesy to ensure your code is readable and not full of major security holes.

It is readable, perhaps not formatted, but many IDE will do that for you if you need it.

Of course it should not have security holes, no doubt about that, but this is the first major security hole since the first release, which is dated 20060311.

I have no intension of putting security holes into the script, but it's human made, errors are bound to occur. I can think of some blogging platform used on many many more sites that also has security holes found every now and then.

I don't tell people to use my script, and I never said it's bug free. It's free and you get what you pay for.

One more thing, I diden't intend it to be used across hundres of sites, it should be used across one hundred millions of sites! :thumbsup

fluffygrrl 08-28-2007 09:55 AM

Quote:

Originally Posted by LinkEX (Post 12998501)
I don't see why I should. As I recall you either have or are using LinkEX on your site(s), never heard any "thank you" from you?

The only thing I regret is the trouble people is going to have, since they have to update their installations, because of a stupid mistake.
There are properly many more bugs in LinkEX, but you get what you pay for, and I don't feel like apologise for every one of them. You get the script for free, and in return help me come up with ideas and report bugs. :thumbsup

- v0id

Yesm okay, fair enough.

Would you stick the spacing back in ? Please ?

v0id 08-28-2007 11:01 AM

Sure thing.. I'll just have to clean up my messy comments. I'll let you know

u-Bob 08-28-2007 03:30 PM

Quote:

Originally Posted by teg0 (Post 12993722)
Windows = shitty code

and this is relevant how exactly...?

xroach 08-28-2007 03:55 PM

that's probably the most nub security flaw you could write into a program. i'd expect it says something about the rest of the code. this thread is totally deserving, a public service and probably the quickest way to get it fixed. though i'd not be running that script at all anymore until i'd read through it myself.

fluffygrrl 08-28-2007 10:06 PM

Quote:

Originally Posted by xroach (Post 13000977)
though i'd not be running that script at all anymore until i'd read through it myself.

From what the man's saying, he's gonna fix it so you can do just that.

v0id 08-29-2007 11:23 PM

released a new version with the spaces, I'll make it better formatted in the future, but this will do for now.
Have fun, and please report any bugs you encounter :)

fluffygrrl 08-30-2007 01:06 AM

Quote:

Originally Posted by LinkEX (Post 13007809)
released a new version with the spaces, I'll make it better formatted in the future, but this will do for now.
Have fun, and please report any bugs you encounter :)

There you go. Time to change my siggy then.

tenderobject 08-30-2007 02:41 AM

Quote:

Originally Posted by LinkEX (Post 12999262)
Yup

Code:

/path/to/php /path/to/your/linkex/index.php[ --verbose]
will check the backlinks, use the --verbose to have it write the results to stdout

does the code you gave me to check backlinks will still work with this update

anyways, ive just upgraded my linkEx to 6 of my sites. heh when will you release a paid linkEx which we can manage linkEx sites in one directory? upgrade/add/check links in one dmin would be awesome man. i won't hesitate to pay for the script.

Why 08-30-2007 03:38 AM

the fix is retardedly easy. if you are using linkex and it concerns you, go fix it.

d-null 08-30-2007 03:44 AM

I'm impressed by LinkEX's attitude, seems like a really good guy :thumbsup:thumbsup

pussyluver 08-31-2007 12:06 AM

Thanks for the use of the FREE script. Some applications call for a simple easy solution. LinkEx fills a need.

Your thick skin in taking the abuse is also appreciated and respected. :thumbsup

zigx 09-04-2007 09:43 PM

can linkex handle a large site??

minusonebit 09-06-2007 02:59 PM

Bump for those who have not yet seen this and fixed their shit... :-)

d-null 09-06-2007 09:14 PM

bump again


All times are GMT -7. The time now is 02:44 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123