Cronwerks MCCode/MCCodes Forums

Please login or register.

Login with username, password and session length

News:

Have you purchased a mod and lost your copy? Just file a support ticket through your "My Mods" page.


This forum is now closed and has moved to a new location! Click here to find out why.
Pages: [1] 2

AuthorTopic: Help about Session Hack  (Read 3583 times)

benlakaz

  • Basic Member
  • *
  • Reputation Power: 4
  • benlakaz has no influence.
  • Offline Offline
  • Posts: 10
    • View Profile
Help about Session Hack
« on: July 02, 2009, 12:43:49 AM »
is there any script to avoid session hack in mccodes v2?
because I experienced my mccodes v2 being hacked by a user an he became admin.. thanks
Logged

Cronus

  • Administrator
  • Senior Member
  • *****
  • Reputation Power: 2901
  • Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!Cronus is awe-inspiring!
  • Offline Offline
  • Posts: 550
    • MSN Messenger - preston__08@hotmail.com
    • View Profile
    • WWW
Re: Help about Session Hack
« Reply #1 on: July 02, 2009, 03:39:55 AM »
I really doubt he used a session hack.
There are a lot more options that seem far more likely.
Logged
My msn is preston__08@hotmail.com if anyone is interested, I am online frequently.

benlakaz

  • Basic Member
  • *
  • Reputation Power: 4
  • benlakaz has no influence.
  • Offline Offline
  • Posts: 10
    • View Profile
Re: Help about Session Hack
« Reply #2 on: July 03, 2009, 02:07:19 AM »
what should i do to avoid this?
Logged

ChrisJonesCJ

  • Basic Member
  • *
  • Reputation Power: 6
  • ChrisJonesCJ has no influence.
  • Offline Offline
  • Posts: 15
    • View Profile
Re: Help about Session Hack
« Reply #3 on: September 30, 2009, 03:36:45 PM »
"what should i do to avoid this?"

1: Dont use an obvious password make sure it's something long and complex such as random letters numbers.
Use a diffrent username to your login name.

2: Obvious but dont share your account details with ANYONE ! not a coder who is offering your help or a close friend.

3: Learn to code.


From MY experience with mccode I dont think you where session hacked but why not search mccode related forums for security updates (just search the word security)

that would be a good easy start.

Logged

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: Help about Session Hack
« Reply #4 on: October 01, 2009, 09:15:48 AM »
i bet you were forum hacked.
Logged
Project Choosen - 10%
Daniel - Hanson . Com

strats

  • Active Member
  • **
  • Reputation Power: 13
  • strats has no influence.
  • Offline Offline
  • Posts: 109
    • View Profile
Re: Help about Session Hack
« Reply #5 on: October 02, 2009, 07:43:37 AM »
Secure your forum. Here a some secure forums :
http://www.cronwerks.com/forum/cronwerks-free-mccode-mccodes-mods/(mccode)-secured-advanced-forums/
I found this one very easy to use :
http://dev-forum.net/index.php/topic,666.0.html


Also making sure you secure pages like your login.php, authenticate.php
register.php  x 2 and header.php

To secure these pages you must find,

Code: [Select]
$IP = ($_SERVER['HTTP_X_FORWARDED_FOR'])
? $_SERVER['HTTP_X_FORWARDED_FOR']
: $_SERVER['REMOTE_ADDR'];

And replace with,

$IP = $_SERVER['REMOTE_ADDR'];


There are many other pages with small bugs and un secure pages you would have to search through them all.
Logged

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: Help about Session Hack
« Reply #6 on: October 03, 2009, 04:32:22 AM »
For MTG's forums you will need Php5
Logged
Project Choosen - 10%
Daniel - Hanson . Com

strats

  • Active Member
  • **
  • Reputation Power: 13
  • strats has no influence.
  • Offline Offline
  • Posts: 109
    • View Profile
Re: Help about Session Hack
« Reply #7 on: October 07, 2009, 03:50:10 PM »
I was hacked the other day through the preference page.
The best thing for that is to make it so users have to upload pictures from their computer to your site.
This way users can not abuse the display pic thingy lol
Logged

ryantommo

  • Basic Member
  • *
  • Reputation Power: 10
  • ryantommo has no influence.
  • Offline Offline
  • Posts: 3
    • View Profile
    • Email
Re: Help about Session Hack
« Reply #8 on: October 15, 2009, 11:42:32 AM »
It is session hijacking people did it on my game untill i found it out what they do is

put this as there display picture > staff_special.php?action=user_level=blah n so on

so that when you visit there profile it makes them admin there is ways to stop this using a few different things you can post MTG's mod where it doesnt let them do it or one where it makes sure they type in a .jpg file is a nasty glitch and is pretty gutting to a site when users can make themself admin i suggest u fix it :/
Logged

gambino

  • Active Member
  • **
  • Reputation Power: 0
  • gambino is looked down upon.gambino is looked down upon.gambino is looked down upon.
  • Offline Offline
  • Posts: 113
    • View Profile
Re: Help about Session Hack
« Reply #9 on: October 30, 2009, 04:12:16 AM »
if you PM me, I will help you on securing your site. I have scripts that really do work.
Logged

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: Help about Session Hack
« Reply #10 on: October 30, 2009, 12:53:41 PM »
No script will secure a site. Get it in your head.
Logged
Project Choosen - 10%
Daniel - Hanson . Com

gambino

  • Active Member
  • **
  • Reputation Power: 0
  • gambino is looked down upon.gambino is looked down upon.gambino is looked down upon.
  • Offline Offline
  • Posts: 113
    • View Profile
Re: Help about Session Hack
« Reply #11 on: October 30, 2009, 01:27:23 PM »
dude. you just don't know because I had people give them self lots of money, crystals, high stats, donater days, give other people stuff, and change them selfs into admins. I found out what they are using to get that and I created a code that blocks it and no one can do any hack. just PM me and I will give you the code.
Logged

Jordan

  • Active Member
  • **
  • Reputation Power: 55
  • Jordan has no influence.
  • Offline Offline
  • Posts: 102
  • Website Developer for hire;
    • MSN Messenger - Pudda2008@hotmail.co.uk
    • View Profile
    • WWW
    • Email
Re: Help about Session Hack
« Reply #12 on: October 31, 2009, 07:59:36 AM »
dude. you just don't know because I had people give them self lots of money, crystals, high stats, donater days, give other people stuff, and change them selfs into admins. I found out what they are using to get that and I created a code that blocks it and no one can do any hack. just PM me and I will give you the code.

Due to the amount of script kiddies around I highly doubt that
Logged
Contact me
MakeWebGames.com

gambino

  • Active Member
  • **
  • Reputation Power: 0
  • gambino is looked down upon.gambino is looked down upon.gambino is looked down upon.
  • Offline Offline
  • Posts: 113
    • View Profile
Re: Help about Session Hack
« Reply #13 on: October 31, 2009, 03:20:32 PM »
you can hold on the security for a sec. someone planned to take my friends codes away and planned to sell them illegally just to keep his server up and running. we are trying to get an other server running when we can.

not giving the code out until resolved with a new server and the lawyer and McCodes takes care of them.
Logged

gambino

  • Active Member
  • **
  • Reputation Power: 0
  • gambino is looked down upon.gambino is looked down upon.gambino is looked down upon.
  • Offline Offline
  • Posts: 113
    • View Profile
Re: Help about Session Hack
« Reply #14 on: October 31, 2009, 05:55:14 PM »
actually, since I had the code active, it will take me a while to recover it. I will make it a file and have it as an include file for the header. since my friend had his server taken away by the last hosting provider, my friend is tired of having his game named the way he had it, he deleted his domain name and discontinued selling and having it up. my friend handed me a contract and what it is, is a partnership contract. meaning if he doesn't want his site anymore, I'm the owner of the site. he is making the site the way I want it named and we both are coding it.

expect the game to be good because it will be online when we can get it running first.
Logged
Pages: [1] 2
« previous next »
 


This forum is now closed and has moved to a new location! Click here to find out why.