Jump to content
  • 1

Security to all hackers.


Hatake Kakashi

Question


  • Group:  Members
  • Topic Count:  254
  • Topics Per Day:  0.06
  • Content Count:  825
  • Reputation:   3
  • Joined:  11/14/11
  • Last Seen:  

i need a security to avoid SQL injections. or firewall from those hackers. please help thanks

damn here's hacker ip. ban his ip guys. so that never happen in your server.

112.200.171.112

Edited by hatake
Link to comment
Share on other sites

Recommended Posts


  • Group:  Members
  • Topic Count:  47
  • Topics Per Day:  0.01
  • Content Count:  633
  • Reputation:   78
  • Joined:  11/14/11
  • Last Seen:  

Try to lessen the commands that the application can execute in SQL like only allowing them to Select, Update, Delete and Insert which are the basic sql commands.

I also found this in our Hostgator webpanel it offers website security: http://www.sitelock.com/landing/hostgator.php

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  25
  • Topics Per Day:  0.01
  • Content Count:  257
  • Reputation:   253
  • Joined:  11/29/11
  • Last Seen:  

Ceres and FluxCP are completely safe if used correctly.

If settings are left at their defaults and modifications are applied that are not penetration tested correctly, bad things happen.

There is absolutely nothing wrong with either CP package, merely the idiots who use them incorrectly.

If you were hacked, you were obviously foolish enough to leave a security exploit to begin with such as a default password or misconfiguration security setting.

It is not our job to teach you common sense- perhaps if you lack the proper understanding of basic security measurements server hosting is not for you. A game server as *Athena may be, basic security features/practices still apply to it.

  • Upvote 5
Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  35
  • Topics Per Day:  0.01
  • Content Count:  103
  • Reputation:   0
  • Joined:  11/13/11
  • Last Seen:  

Ceres and FluxCP are completely safe if used correctly.

If settings are left at their defaults and modifications are applied that are not penetration tested correctly, bad things happen.

There is absolutely nothing wrong with either CP package, merely the idiots who use them incorrectly.

If you were hacked, you were obviously foolish enough to leave a security exploit to begin with such as a default password or misconfiguration security setting.

It is not our job to teach you common sense- perhaps if you lack the proper understanding of basic security measurements server hosting is not for you. A game server as *Athena may be, basic security features/practices still apply to it.

+1

The fluxcp safe just so he said not safe for addons such as CMS just try without addons to see us be able to hack you

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  8
  • Topics Per Day:  0.00
  • Content Count:  206
  • Reputation:   16
  • Joined:  01/03/12
  • Last Seen:  

ok fine, i dont need help anymore for this issue. f**k all those want a money only for doing helping people regarding with this issue. sorry mods for my foul language, because i want to spread my feelings. thank you..

Seriously what's with the animosity? Someone gave you the best help, they pointed you to knowledge. In the future please research things. Don't expect people to do something for you. Most things on not having time is priority, you make time for what's important to you.

As for things like sql injection phpacademy on youtube has some basic tutorials on how to do sql injection and how to prevent it. There are several resources out there. I actually would not recommend writing your own CP until you get pretty advanced in PHP or some other serverside scripting as you could actually end up making something even less secure. The best tool you can have against hacking is knowledge. Learn it.

Edited by Sinon Yoshida
Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  18
  • Topics Per Day:  0.00
  • Content Count:  94
  • Reputation:   0
  • Joined:  11/26/11
  • Last Seen:  

Hatake Kakashi : actually every CP is not secured . even SGCP , FluxCP , CeresCP , they aren`t secured . just depends on your website.. check for vulnable and plant something inside .. thats should help :P

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  3
  • Topics Per Day:  0.00
  • Content Count:  707
  • Reputation:   168
  • Joined:  01/26/12
  • Last Seen:  

Ceres and FluxCP are completely safe if used correctly.

If settings are left at their defaults and modifications are applied that are not penetration tested correctly, bad things happen.

There is absolutely nothing wrong with either CP package, merely the idiots who use them incorrectly.

If you were hacked, you were obviously foolish enough to leave a security exploit to begin with such as a default password or misconfiguration security setting.

It is not our job to teach you common sense- perhaps if you lack the proper understanding of basic security measurements server hosting is not for you. A game server as *Athena may be, basic security features/practices still apply to it.

Hi Hatake Kakashi,

The only person in this whole topic which is speaking the absolute truth is CalciumKid. SQL Injection is not possible for FluxCP because of the way it parses the SQL requests in it's panel system.

If you had your own website, and tried to improperly integrate Flux; then I can see there might be a chance of vulnerability for SQL Injection. Or if there was an add-on you used, which was poorly coded.

A firewall will not protect you from a SQL Injection, nor blocking ports.

Edited by Asura
Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  9
  • Topics Per Day:  0.00
  • Content Count:  379
  • Reputation:   304
  • Joined:  11/10/11
  • Last Seen:  

No.

My exploit isn't related to SQL injection, it allow to use other users privileges to perform specify actions in the panel.

If Calcium' wants to fix it, he can contact me; but I don't know about the future of FluxCP with paradox laziness and rathena new features.

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  6
  • Topics Per Day:  0.00
  • Content Count:  24
  • Reputation:   0
  • Joined:  03/15/12
  • Last Seen:  

Ceres and FluxCP are completely safe if used correctly.

If settings are left at their defaults and modifications are applied that are not penetration tested correctly, bad things happen.

There is absolutely nothing wrong with either CP package, merely the idiots who use them incorrectly.

If you were hacked, you were obviously foolish enough to leave a security exploit to begin with such as a default password or misconfiguration security setting.

It is not our job to teach you common sense- perhaps if you lack the proper understanding of basic security measurements server hosting is not for you. A game server as *Athena may be, basic security features/practices still apply to it.

+1

The fluxcp safe just so he said not safe for addons such as CMS just try without addons to see us be able to hack you

Ceres and FluxCP are completely safe if used correctly.

If settings are left at their defaults and modifications are applied that are not penetration tested correctly, bad things happen.

There is absolutely nothing wrong with either CP package, merely the idiots who use them incorrectly.

If you were hacked, you were obviously foolish enough to leave a security exploit to begin with such as a default password or misconfiguration security setting.

It is not our job to teach you common sense- perhaps if you lack the proper understanding of basic security measurements server hosting is not for you. A game server as *Athena may be, basic security features/practices still apply to it.

Hi Hatake Kakashi,

The only person in this whole topic which is speaking the absolute truth is CalciumKid. SQL Injection is not possible for FluxCP because of the way it parses the SQL requests in it's panel system.

If you had your own website, and tried to improperly integrate Flux; then I can see there might be a chance of vulnerability for SQL Injection. Or if there was an add-on you used, which was poorly coded.

A firewall will not protect you from a SQL Injection, nor blocking ports.

My fluxcp has a CMS add on as well as helloworld and vote_for_credits. Do you think these made my flux vulnerable to sql injection attacks?

So do you mean that by using default flux addons or no addons then it will already be secured? I just want verification so I will revert everything back to default if needed just to be secured. Because right now my database is being attacked. He was able to generate items using query. He can search for accounts and know the password/s and he can even change a character name to a name with special characters like !@#$%^&*() which is not supported by character creation by default. He also can unban a banned account. Clearly he has access to my database!

Please give me enlightenent.

Thank you.

Edited by gunman
Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  3
  • Topics Per Day:  0.00
  • Content Count:  707
  • Reputation:   168
  • Joined:  01/26/12
  • Last Seen:  

Hi Gunman,

I would suggest that you remove any add-ons which may not be up to date; also change all your passwords/account names for MySQL access. This will be the only absolute way that you can remove any possibility of this person further damaging your database.

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  87
  • Topics Per Day:  0.02
  • Content Count:  1335
  • Reputation:   932
  • Joined:  10/26/11
  • Last Seen:  

lol with this guy really...

He says "I dont have the time to read, or to learn bla bla bla" and he asks other users to make the work for him, just because he wants and he is upset if someone will charge for that...

Excuse me but, what a loser. Protect something agains PHP/SQL Hacking methods, it is not like requesting a script, or simple things... It is something very extensive that if you want to be 100% sure, you can't trust anyone to do that work for you.

It is something made progressly, and it is necessary to be up to date to date with it, every time... so who will have the time to do this for you everyday? no one. Start to learn if you feel disrespected with paying for the time of SOMEONE and good luck.

Edited by Olrox
  • Upvote 2
Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  40
  • Topics Per Day:  0.01
  • Content Count:  530
  • Reputation:   33
  • Joined:  01/17/12
  • Last Seen:  

lol with this guy really...

He says "I dont have the time to read, or to learn bla bla bla" and he asks other users to make the work for him, just because he wants and he is upset if someone will charge for that...

Excuse me but, what a loser. Protect something agains PHP/SQL Hacking methods, it is not like requesting a script, or simple things... It is something very extensive that if you want to be 100% sure, you can't trust anyone to do that work for you.

It is something made progressly, and it is necessary to be up to date to date with it, every time... so who will have the time to do this for you everyday? no one. Start to learn if you feel disrespected with paying for the time of SOMEONE and good luck.

+1000000 LOL totally agree ( :) where's Super Girl)

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  87
  • Topics Per Day:  0.02
  • Content Count:  1335
  • Reputation:   932
  • Joined:  10/26/11
  • Last Seen:  

oh well she is in my heart <3! hahaha I'm not sure I think this one is cute too, don't you think? D:

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  20
  • Topics Per Day:  0.00
  • Content Count:  145
  • Reputation:   15
  • Joined:  01/06/12
  • Last Seen:  

Posted · Hidden by Emistry, March 23, 2012 - Post with just a word "LOL"
Hidden by Emistry, March 23, 2012 - Post with just a word "LOL"

LOL.

Link to comment

  • Group:  Members
  • Topic Count:  40
  • Topics Per Day:  0.01
  • Content Count:  530
  • Reputation:   33
  • Joined:  01/17/12
  • Last Seen:  

she looks ok, but Super Girl is just Super !!

sorry offtopic LOL..

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  8
  • Topics Per Day:  0.00
  • Content Count:  206
  • Reputation:   16
  • Joined:  01/03/12
  • Last Seen:  

lol with this guy really...

He says "I dont have the time to read, or to learn bla bla bla" and he asks other users to make the work for him, just because he wants and he is upset if someone will charge for that...

Excuse me but, what a loser. Protect something agains PHP/SQL Hacking methods, it is not like requesting a script, or simple things... It is something very extensive that if you want to be 100% sure, you can't trust anyone to do that work for you.

It is something made progressly, and it is necessary to be up to date to date with it, every time... so who will have the time to do this for you everyday? no one. Start to learn if you feel disrespected with paying for the time of SOMEONE and good luck.

I totally agree. I guess some people just aren't willing to have the patience or do the research. His loss I guess.

Edited by Shinon Yoshida
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...