Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-14-2008, 11:17 PM   #1
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
free tube script w/auto updating embed codes

I'm just about to finish up on a free tube script which has auto updating embedded videos from a friends DB of videos. I am also finishing up on an addon which will be available for a small fee which will import embed codes from some of the top tube sites.

I'll have a first release of the system sometime tomorrow and will be adding a few extra things into it later in the week.

Also when I get the SPONSORED content addons together for ES I'll also port them down to this free version for additional addons.

Anybody looking for a simple system that they can simply toss up without spending a dime and quickly have thousands of videos and start getting indexed this will be a very nice place to start a site. I'll be building some quick upgrade tools so that once you're getting traffic and profiting you can easily upgrade to the paid script. Any addons you've purchased for the free system will be able to work with the paid script! My plan is to charge a small fee for packages of supporting like 3-5 either embed codes for tube sites or sponsored videos. All to be able to quickly get your site up and running and only paying for what you'll actually use instead of paying $70+ just to get a site launched.

If you're interested in being one of the first ones up on this post here!
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2008, 11:54 PM   #2
c0ld
Confirmed User
 
Join Date: Mar 2006
Location: Belgium
Posts: 435
Got a demo?
__________________
1:34
my icq: 239730866
c0ld is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 05:51 PM   #3
mryellow
Confirmed User
 
Industry Role:
Join Date: May 2001
Location: Australia
Posts: 934
Quote:
addon which will be available for a small fee which will import embed codes from some of the top tube sites.
Bad idea..... The listings on a site are copyright.

Steal thehun's or PKs links and start a TGP with them and see how that goes down.

-Ben
__________________
Cyberwurx Hosting
After trying 5 different hosts, I found the best.
Since 1997 I've had 2 hours of downtime.
Fast support, great techs, no hype, no gimmicks.

<- I in no way endorse whatever just got stuck on the left of my post.
mryellow is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 05:56 PM   #4
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by mryellow View Post
Bad idea..... The listings on a site are copyright.

Steal thehun's or PKs links and start a TGP with them and see how that goes down.

-Ben
if the site in question has an embed code for others to share the video, then what is wrong?
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 05:59 PM   #5
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by mryellow View Post
Bad idea..... The listings on a site are copyright.

Steal thehun's or PKs links and start a TGP with them and see how that goes down.

-Ben
i dont see how that would be a problem. I can certainly start a tgp and copy the hun's links onto my site. if i copy his link text or logo's i might have a problem , but theres no law against having the same links as another site as far as i am aware
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 07:14 PM   #6
mryellow
Confirmed User
 
Industry Role:
Join Date: May 2001
Location: Australia
Posts: 934
Sure if they syndicate their feed for others to use and you use it within the TOS.
However don't just suck videos outta pages or anything like that.

Yeah Smokey there was a massive blowup about it a while back, people were being
hunted for stealing links. Courts have shown that the specific collection of links on a site
are copyright the site-owner.

Just like the dictionary has words in it which anyone can use.....
It is still copyright violation to copy a whole dictionary into a new one. (red herrings)

People put alot of hours into building relationships and reviewing submissions, tailoring their site to the market
and weeding out the bad stuff...... If you come along and steal that work and the site-owner knows the
value of that work, and the profit you're making from said work..... you will be sued.

-Ben
__________________
Cyberwurx Hosting
After trying 5 different hosts, I found the best.
Since 1997 I've had 2 hours of downtime.
Fast support, great techs, no hype, no gimmicks.

<- I in no way endorse whatever just got stuck on the left of my post.

Last edited by mryellow; 04-15-2008 at 07:16 PM..
mryellow is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 08:35 PM   #7
Chr0makey
Confirmed User
 
Join Date: Oct 2006
Location: Australia
Posts: 932
Sounds interesting. Let me know when you have something up.
__________________
DDOS ATTACK PROTECTION
Chr0makey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 08:46 PM   #8
qxm
Confirmed User
 
Join Date: Jul 2006
Location: NoHo
Posts: 5,970
very interesting indeed......... hit me up when u have everything ready 266-990-876
__________________

ICQ: 266990876
qxm is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 08:55 PM   #9
johnuno11
Confirmed User
 
johnuno11's Avatar
 
Join Date: Nov 2007
Location: Tampa, FL
Posts: 692
I'm interested.
__________________
Monetize With iStrippers Future VR Adult Technology 2021, I earn $200+ a month for the last 10 years. Simply by Promoting one brand in your signature link...
johnuno11 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 09:02 PM   #10
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
good luck with the project
__________________

__________________

Looking for a custom TUBE SCRIPT that supports massive traffic, load balancing, billing support, and h264 encoding? Hit up Konrad!
Looking for designs for your websites or custom tubesite design? Hit up Zuzana Designs
Check out the #1 WordPress SEO Plugin: CyberSEO Suite
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 09:12 PM   #11
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by mryellow View Post
Yeah Smokey there was a massive blowup about it a while back, people were being
hunted for stealing links. Courts have shown that the specific collection of links on a site
are copyright the site-owner.
i don't doubt that it would be frowned upon , but hadnt seen any cases of it in the legal world unless there was more to it.

i once had a guy long ago furious for me linking to his site and it was just a simple text link, anyways he made legal threats many times , so i put his link on every page just to piss him off, i never heard back from him
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 09:24 PM   #12
lazycash
Troll Patrol
 
Industry Role:
Join Date: Aug 2002
Location: Local Socal
Posts: 15,214
Quote:
Originally Posted by mryellow View Post
Sure if they syndicate their feed for others to use and you use it within the TOS.
However don't just suck videos outta pages or anything like that.

Yeah Smokey there was a massive blowup about it a while back, people were being
hunted for stealing links. Courts have shown that the specific collection of links on a site
are copyright the site-owner.

Just like the dictionary has words in it which anyone can use.....
It is still copyright violation to copy a whole dictionary into a new one. (red herrings)

People put alot of hours into building relationships and reviewing submissions, tailoring their site to the market
and weeding out the bad stuff...... If you come along and steal that work and the site-owner knows the
value of that work, and the profit you're making from said work..... you will be sued.

-Ben
Many of the tube sites purposefully post their embed codes so people will post their videos on other sites. Sure it may cost them bandwidth, but most have their site branding and advertising built into their video player. You may have a point with the tgp, but you're off base on this one.
lazycash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 09:30 PM   #13
mryellow
Confirmed User
 
Industry Role:
Join Date: May 2001
Location: Australia
Posts: 934
Quote:
The Hun, The Hun's Yellow Pages and thehun.net are registered trademarks; the layout and particular characteristics in which these pages appear have full copyright. Any violation of these rights like copying or reproducing these pages are illegal and will be prosecuted to the full extents of the law. "The Hun's Yellow Pages," as a compilation of pre-existing URLs, based upon the selective assembly of specific links from among the universe of available links, is protected under the U.S. Copyright Act, as amended, and the Berne Convention on Copyrights. The Hun expends significant time, energy and resources in bringing you his daily page. Accordingly, individuals or entities identified as copying links from the Hun's Yellow Pages will be considered copyright infringers and will be pursued to the fullest extent of the law.
It's a compilation and copyright.

Steal his links and see :-)

edit: like I said.... It's ok if they allow it..... If you're just ripping vids it's far from ok.

-Ben
__________________
Cyberwurx Hosting
After trying 5 different hosts, I found the best.
Since 1997 I've had 2 hours of downtime.
Fast support, great techs, no hype, no gimmicks.

<- I in no way endorse whatever just got stuck on the left of my post.
mryellow is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 09:36 PM   #14
lazycash
Troll Patrol
 
Industry Role:
Join Date: Aug 2002
Location: Local Socal
Posts: 15,214
Quote:
Originally Posted by mryellow View Post
It's a compilation and copyright.

Steal his links and see :-)

edit: like I said.... It's ok if they allow it..... If you're just ripping vids it's far from ok.

-Ben

The original poster never said anything about ripping vids, he said importing embed codes.
lazycash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2008, 10:53 PM   #15
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by mryellow View Post
It's a compilation and copyright.

Steal his links and see :-)


-Ben
anyone can say anything is copyright , but will it stand up in court i dont know.

also i notice 2 important points you brought up.. #1 u.s. copyright and #2 the berne convention.. there are countries that havent signed the berne convention.


p.s. i did build a hun ripper , it grabs the huns latest galleries and turns the galleries into long videos. Its actually quite a cool tool. I didnt think it was a problem really, it would be awfully hard to steal thehun's thunder especially when most of the galleries have his thumb so even if someone recreated an exact replica of the hun , all the branding is thehun's
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 01:08 AM   #16
NinjaSteve
Too lazy to set a custom title
 
Industry Role:
Join Date: Dec 2003
Posts: 11,089
Sounds cool. I like the demo in your sig.
__________________
...
NinjaSteve is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 03:18 PM   #18
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
sorry I ended up being busy last night, I'm working on it some more now and will have a demo online tonight sometime along with a download link.

the demo link is the paid full system LOL the free one is going to be pretty limited... Trying to figure out what layout I want to use with the free version right now. I'm probably just going to keep it super simple so that people can customize it easier.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --

Last edited by farkedup; 04-16-2008 at 03:21 PM..
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 03:23 PM   #19
karlm
Confirmed User
 
Join Date: Jun 2004
Location: UK
Posts: 4,194
Wow that looks sweet mate
__________________
ICQ 584665926
karlm is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 05:00 PM   #20
x0pa
Confirmed User
 
Join Date: Feb 2007
Location: Winnipeg,Canada
Posts: 275
hit me up im interested
__________________
Hit Me Up ICQ: 482-644-794 .::.HunkMoney.::.BritishBucks.::.LatinoBucks.::.
x0pa is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 05:09 PM   #21
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Quote:
Originally Posted by SmokeyTheBear View Post
anyone can say anything is copyright , but will it stand up in court i dont know.

also i notice 2 important points you brought up.. #1 u.s. copyright and #2 the berne convention.. there are countries that havent signed the berne convention.


p.s. i did build a hun ripper , it grabs the huns latest galleries and turns the galleries into long videos. Its actually quite a cool tool. I didnt think it was a problem really, it would be awfully hard to steal thehun's thunder especially when most of the galleries have his thumb so even if someone recreated an exact replica of the hun , all the branding is thehun's
As I remember the ruling was that a list of links is a database and a database can be protected by copyright. This was all very relevant to me at the time since I was selling a directory TGP script that was capable of harvesting links from other sites.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 07:04 PM   #22
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
This is just modified version of a system I had out like a year ago http://entertainmentscript.com/free/ still in that old template, I'll get around to a more pornhub type layout sometime... if anybody could donate some time to putting something else together I'd appreciate it and get them into a beta for the embed code addon ;)
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 07:53 PM   #23
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
http://entertainmentscript.com/free/free.zip

I didn't get the category display/links put back in yet LOL but I'm heading to bed... I'll get some more work done on this in a few days.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 11:34 PM   #24
Scroto
Confirmed User
 
Scroto's Avatar
 
Join Date: Nov 2005
Posts: 2,804
Quote:
Originally Posted by farkedup View Post
This is just modified version of a system I had out like a year ago http://entertainmentscript.com/free/ still in that old template, I'll get around to a more pornhub type layout sometime... if anybody could donate some time to putting something else together I'd appreciate it and get them into a beta for the embed code addon ;)
Is it just me or does the ratings not work?
Scroto is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-16-2008, 11:43 PM   #25
CyberHustler
Masterbaiter
 
Industry Role:
Join Date: Feb 2006
Posts: 26,177
Sounds nice!
CyberHustler is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 10:46 AM   #26
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
Quote:
Originally Posted by Scroto View Post
Is it just me or does the ratings not work?
In the DB I still had it set for running on localhost LMAO will be fixing this in a minute.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 11:34 AM   #27
Scroto
Confirmed User
 
Scroto's Avatar
 
Join Date: Nov 2005
Posts: 2,804
Quote:
Originally Posted by farkedup View Post
In the DB I still had it set for running on localhost LMAO will be fixing this in a minute.
oops lol looks pretty nice otherwise for a free script
Scroto is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 11:40 AM   #28
Phil
Confirmed User
 
Phil's Avatar
 
Join Date: Jan 2004
Posts: 7,659
good one, ill take a copy
__________________
Ask Phil
Phil is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 11:51 AM   #29
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
Quote:
Originally Posted by Scroto View Post
oops lol looks pretty nice otherwise for a free script
I develop everything locally so I can just hit save in dreamweaver and refresh the page instead of also uploading things. Saves a ton of time when you're doing small edits.

All that you'll need to modify the ads are simply things in the ads/ folder. If you want basic ad rotations its actually quite simple. I'll post up some instructions for this soon.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 01:37 PM   #30
suzieg
Registered User
 
Join Date: Jul 2002
Location: LA
Posts: 39
I am interested. I am free right now and can reserve the entire weekend to getting it up.
suzieg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:07 PM   #31
jimbona
Confirmed User
 
Join Date: Jan 2007
Posts: 190
It might just be me, but reviewing the source it seems its open to injection via _GET and _POST data as it is loaded directly into the SQL queries so hackers will have a field day with this like other free scripts with uncleansed data to SQL.
__________________
Thanks
Paul
Thunder-Ball.net - Member
jimbona is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:17 PM   #32
Barefootsies
Choice is an Illusion
 
Barefootsies's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
:2cents

Quote:
Originally Posted by jimbona View Post
It might just be me, but reviewing the source it seems its open to injection via _GET and _POST data as it is loaded directly into the SQL queries so hackers will have a field day with this like other free scripts with uncleansed data to SQL.
__________________
Should You Email Your Members?

Link1 | Link2 | Link3

Enough Said.

"Would you rather live like a king for a year or like a prince forever?"
Barefootsies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:37 PM   #33
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
Quote:
Originally Posted by jimbona View Post
........like other free scripts..........

just because something is free is not a reason, just as the fact that just because something isn't free doesn't mean it is safe
__________________

__________________

Looking for a custom TUBE SCRIPT that supports massive traffic, load balancing, billing support, and h264 encoding? Hit up Konrad!
Looking for designs for your websites or custom tubesite design? Hit up Zuzana Designs
Check out the #1 WordPress SEO Plugin: CyberSEO Suite
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:40 PM   #34
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
Quote:
Originally Posted by jimbona View Post
It might just be me, but reviewing the source it seems its open to injection via _GET and _POST data as it is loaded directly into the SQL queries so hackers will have a field day with this like other free scripts with uncleansed data to SQL.
sorry it is, I was using a REALLY old codebase of mine. I'll have that fixed up in like 20 minutes or so ;)
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:43 PM   #35
jimbona
Confirmed User
 
Join Date: Jan 2007
Posts: 190
Quote:
Originally Posted by jetjet View Post
just because something is free is not a reason, just as the fact that just because something isn't free doesn't mean it is safe
I know this, im just speaking from the perspective of being around when other known scripts which were free were hacked and became an epidemic:P

Yes, even paid scripts are not safe either, but with free you can review source(anyone can) but with a paid product a person would have to spend money first, then have to review to script.

Anyway, just raising awareness that people should review the code before putting it live on a site and wondering why it was hacked so quickly.
__________________
Thanks
Paul
Thunder-Ball.net - Member
jimbona is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:45 PM   #36
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
with a quick scan it looks like rating.php is the only file that actually takes user data up top simply changing to this:
Code:
$gameid			= mysql_real_escape_string($_POST['gameid']);
$gameid2		= mysql_real_escape_string($_POST['gameid']);
$score			= mysql_real_escape_string($_POST['score']);
cleans the data before MySQL actually uses it. I'm going to keep looking around for anything outside the admin panel but with a quick look that appears to be the only thing vulnerable.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:48 PM   #37
jimbona
Confirmed User
 
Join Date: Jan 2007
Posts: 190
Quote:
Originally Posted by farkedup View Post
sorry it is, I was using a REALLY old codebase of mine. I'll have that fixed up in like 20 minutes or so ;)
I know its an old codebase, im seen it used several times.

You may also want to check the admin for references to games/game files and they wont be relevant in a video embed site.
__________________
Thanks
Paul
Thunder-Ball.net - Member
jimbona is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 03:57 PM   #38
jimbona
Confirmed User
 
Join Date: Jan 2007
Posts: 190
Quote:
Originally Posted by farkedup View Post
with a quick scan it looks like rating.php is the only file that actually takes user data up top
Might want to recheck,

files open to abuse:

category.php-$cid
search.php-$cid-$search
play.php-$id-$id2

function/template files could be open to abuse if register_globals is on.
__________________
Thanks
Paul
Thunder-Ball.net - Member
jimbona is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 04:00 PM   #39
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
I'm uploading a minor update now that fixes the work game in a few places along with that rating.php update and an updated config.php that simply added this:

Code:
if (isset($_POST)){
$ip2 = (empty($_SERVER['REMOTE_ADDR'])) ? 'empty' : $_SERVER['REMOTE_ADDR'];
$ua = (empty($_SERVER['HTTP_USER_AGENT'])) ? 'empty' : $_SERVER['HTTP_USER_AGENT'];
$ru = (empty($_SERVER['REQUEST_URI'])) ? 'empty' : $_SERVER['REQUEST_URI'];
$rm = (empty($_SERVER['REQUEST_METHOD'])) ? 'empty' : $_SERVER['REQUEST_METHOD'];
if ($ua == "empty") { exit();}   
if ($ua == "-") 	{ exit();}
if ($ip2 == "empty"){ exit();} 
if ($ru == "empty") {exit();}   
if ($rm == "empty") { exit();}   
}
it rejects forms from various bots
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 04:14 PM   #40
qxm
Confirmed User
 
Join Date: Jul 2006
Location: NoHo
Posts: 5,970
Quote:
Originally Posted by jimbona View Post
It might just be me, but reviewing the source it seems its open to injection via _GET and _POST data as it is loaded directly into the SQL queries so hackers will have a field day with this like other free scripts with uncleansed data to SQL.
__________________

ICQ: 266990876
qxm is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 04:22 PM   #41
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
alright, just uploaded a version that cleans get and post vars where needed.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 04:30 PM   #42
PornGeneral
Confirmed User
 
Join Date: Sep 2004
Location: In front of computer
Posts: 564
Code:
$_POST = array_map('mysql_real_escape_string', $_POST);
$_GET = array_map('mysql_real_escape_string', $_GET);
$_COOKIE = array_map('mysql_real_escape_string', $_COOKIE);
Code:
function clean($value){	
   if (get_magic_quotes_gpc()) {	
     $value = stripslashes($value);
   }
   if (!is_numeric($value)) {
     $value = mysql_real_escape_string($value);
   }

 return $value;
} 
array_walk($_GET,'clean');
array_walk($_POST,'clean');
array_walk($_COOKIE,'clean'); 
extract($_GET,EXTR_PREFIX_ALL,'get');
extract($_POST,EXTR_PREFIX_ALL,'post');
extract($_COOKIE,EXTR_PREFIX_ALL,'cookie');
Some old code I use to clean up so far no issues
__________________
"The object of war is not to die for your country but to make the other bastard die for his." -Patton
"Only the dead have seen the end of war." -Plato
PornGeneral is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 05:04 PM   #43
PornGeneral
Confirmed User
 
Join Date: Sep 2004
Location: In front of computer
Posts: 564
Don't forget some xss cleaning functions

Code:
// Prep user input for storage - XSS cleanup
function xss_input($input) { 
    $input = trim($input); 
    if (!get_magic_quotes_gpc()) { 
        return addslashes($input); 
    } 
    return $input; 
} 

// Prep user inputed data for viewing in html page, textbox, or textarea
function xss_output($output) { 
    $output = stripslashes($output); 
    return htmlspecialchars($output); 
}
__________________
"The object of war is not to die for your country but to make the other bastard die for his." -Patton
"Only the dead have seen the end of war." -Plato
PornGeneral is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 05:52 PM   #44
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
this is a variation of what I use in some other scripts which I just put into this one:

Code:
foreach($_POST as $varName => $value)
  {
     $dv=$value;
if (get_magic_quotes_gpc()) {	 $$varName = stripslashes($dv); }
if (!is_numeric($value)) {    $$varName = mysql_real_escape_string($dv);  }
   }; 
   
   foreach($_GET as $varName => $value)
  {
    $dv=$value;
if (get_magic_quotes_gpc()) {	 $$varName = stripslashes($dv); }
if (!is_numeric($value)) {    $$varName = mysql_real_escape_string($dv);  }
   };
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 07:39 PM   #45
Doctor Feelgood
Confirmed User
 
Doctor Feelgood's Avatar
 
Industry Role:
Join Date: Nov 2005
Location: RI
Posts: 2,112
1) can you have the videos higher up the page so i dont have to scroll down?

2) can the 300x250 adspace be edited to 250x250 by webmaster?
Doctor Feelgood is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 07:49 PM   #46
Boozer
So Fucking Banned
 
Join Date: Feb 2005
Posts: 3,134
Just so you know, your template does not look right under firefox
Boozer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 07:52 PM   #47
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
you should get icq
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2008, 08:40 PM   #48
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
Quote:
Originally Posted by Doctor Feelgood View Post
1) can you have the videos higher up the page so i dont have to scroll down?

2) can the 300x250 adspace be edited to 250x250 by webmaster?
1) I don't have to scroll ;) the box above the videos can be tossed down under simple enough. Edit templates/play_content.tpl

2) thats easy enough, go into ads/250x250.tpl I actually don't see 300x250 ads, 250x250 is used everywhere I'm seeing.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2008, 09:33 AM   #49
x0pa
Confirmed User
 
Join Date: Feb 2007
Location: Winnipeg,Canada
Posts: 275
so... is the new version more secure now?
__________________
Hit Me Up ICQ: 482-644-794 .::.HunkMoney.::.BritishBucks.::.LatinoBucks.::.
x0pa is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-18-2008, 10:45 AM   #50
farkedup
Confirmed User
 
Join Date: Nov 2007
Location: Kalamazoo, MI
Posts: 2,490
Quote:
Originally Posted by x0pa View Post
so... is the new version more secure now?
yes, right before my post above I had applied some security updates to the package.
__________________
-- QUOTE ME IT MAKES ME FEEL SPECIAL --
farkedup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.