Cronwerks MCCode/MCCodes Forums

Please login or register.

Login with username, password and session length

News:

Have you purchased a mod and are struggling to install it? Cronwerks now installs mods for only $3/$2.50. Message Cronus to discuss the details or purchase.


This forum is now closed and has moved to a new location! Click here to find out why.
Pages: 1 [2]

AuthorTopic: A LIST of All the Exploits I am aware of  (Read 3163 times)

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: A LIST of All the Exploits I am aware of
« Reply #15 on: February 18, 2010, 06:08:02 AM »
My preg_replace skills arent that hot yet and i've yet to venture into that field

Besides the fact stripslashes(htmlentities appears to work just well.

Either way I'd recommend, but at least do one of them ><

Jordan

  • Active Member
  • **
  • Reputation Power: 55
  • Jordan has no influence.
  • Offline Offline
  • Posts: 102
  • Website Developer for hire;
    • MSN Messenger - Pudda2008@hotmail.co.uk
    • View Profile
    • WWW
    • Email
Re: A LIST of All the Exploits I am aware of
« Reply #16 on: February 19, 2010, 02:53:48 PM »
Besides the fact stripslashes(htmlentities appears to work just well.
Either way I'd recommend, but at least do one of them ><

Couldn't off said it better myself =] :P
Logged
Contact me
MakeWebGames.com

CrimGame.com

  • Basic Member
  • *
  • Reputation Power: 21
  • CrimGame.com has no influence.
  • Offline Offline
  • Posts: 42
  • Play with me baby!
    • View Profile
    • WWW
Re: A LIST of All the Exploits I am aware of
« Reply #17 on: February 20, 2010, 11:31:35 AM »
I'd say Preg Match would be the better result but yes either way you do need to do something, it all depends on what your doing.

Agon

  • Basic Member
  • *
  • Reputation Power: 13
  • Agon has no influence.
  • Offline Offline
  • Posts: 19
    • View Profile
Re: A LIST of All the Exploits I am aware of
« Reply #18 on: July 12, 2010, 01:10:54 PM »
BUMP!

This thread is almost a shame for Mccodes. Maybe it should be deleted and re-written. Or maybe the fixes to these exploits should be posted.
Logged

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: A LIST of All the Exploits I am aware of
« Reply #19 on: July 13, 2010, 11:59:59 AM »
Mcc said they fixed it, shows how good it is right.
Cant wait till i get my copy of mcc 3 :D
Logged
Project Choosen - 10%
Daniel - Hanson . Com

kieranrobo

  • Basic Member
  • *
  • Reputation Power: 62
  • kieranrobo has no influence.
  • Offline Offline
  • Posts: 26
    • View Profile
Re: A LIST of All the Exploits I am aware of
« Reply #20 on: July 16, 2010, 04:41:17 AM »
cmarket.php----crystals hack that if the ID variable is not secured will max out a users crystals.

Ok i need a fix to this one FAST! A guy is threatning with flooding my game with points if i dont give him $100 ::)

Ive banned him but hes using proxys, and has 3 million crystles every time...

FIX FIX FIX!

dominion

  • Active Member
  • **
  • Reputation Power: 89
  • dominion barely matters.dominion barely matters.
  • Offline Offline
  • Posts: 129
    • View Profile
    • Email
Re: A LIST of All the Exploits I am aware of
« Reply #21 on: July 16, 2010, 07:56:39 AM »
sure i will fix it for $100? lol joke  :P

use the cmarket posted http://www.cronwerks.com/forum/cronwerks-free-mccode-mccodes-mods/(mccode)-secured-crystal-market/
do not use cronus' post use the one down a little by maketextgames
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: A LIST of All the Exploits I am aware of
« Reply #22 on: October 11, 2010, 07:42:12 PM »
quick fix

open up header.php

$_GET['ID'] = abs((int) $_GET['ID']);

Or find one of many secured cmarkets lurking on the forums.

Or go through and secure your varibles when you have time.

Do not rely on just the $_GET['ID'] in the header to secure everything, but it will stop the script kiddies ;)
Pages: 1 [2]
« previous next »
 


This forum is now closed and has moved to a new location! Click here to find out why.