Cronwerks MCCode/MCCodes Forums

Please login or register.

Login with username, password and session length

News:

Have errors in your coding or want something specific added to your game? Check out our paid support here.


This forum is now closed and has moved to a new location! Click here to find out why.
Pages: [1] 2

AuthorTopic: mccodes v2 security  (Read 3030 times)

JanArve

  • Basic Member
  • *
  • Reputation Power: 3
  • JanArve has no influence.
  • Offline Offline
  • Posts: 7
    • View Profile
mccodes v2 security
« on: November 08, 2009, 10:30:24 PM »
Hello all,

I bought v2 some time ago, but due to too many projects and too little time I just got around to looking at starting it up.

However, there is something that concerns me a lot! And that is the security of the script, when buying, obviously I expected the script to be as secure as possible as I've paid $300 for it, but everywhere I turn I read about more and more security flaws.

Personally I'm no expert in php and even less when it comes to securing the script.

I would be very interested in knowing exactly how the script is unsecure, and how to fix it. Now, I'm not looking for someone to do it for me, I'm asking for a guidance so I can know what to look for.

For example: "every page where the script does this or that opens it up for this type of attack".

If anyone can tell me such information I would be most gratefull.

Thank you all very much for your time.
Logged

strats

  • Active Member
  • **
  • Reputation Power: 13
  • strats has no influence.
  • Offline Offline
  • Posts: 109
    • View Profile
Re: mccodes v2 security
« Reply #1 on: November 09, 2009, 04:47:51 AM »
Yea I wasn't too happy with paying for V2 and getting so many problems
Logged

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #2 on: November 09, 2009, 11:28:17 AM »
Event Post and Get variable,  needs to be secured, The main problems are Cmarket, Forums, IP hack, and prefs hack.
Logged
Project Choosen - 10%
Daniel - Hanson . Com

JanArve

  • Basic Member
  • *
  • Reputation Power: 3
  • JanArve has no influence.
  • Offline Offline
  • Posts: 7
    • View Profile
Re: mccodes v2 security
« Reply #3 on: November 09, 2009, 01:15:16 PM »
So you're telling me that not even POST and GET are secured?

Thanks for the main problems, do you know what the lesser problems are?
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #4 on: November 09, 2009, 02:07:32 PM »
A list from me to you.

Secure the following

All $_GET and $_POST variables

If its an integer  abs(@intval

if it's a string   mysql_real_escape_string or $db->escape (use MRES)

Top Priorities
$IP above all else

1.  Cmarket.
2.  Forums.
3.  Userlist
4.  Preferances.
5.  Player Report
6.  Bug Report ( if you have )
7.  Viewuser
8.  Player Ads ( if you have )
9.  Item Shops / itemuse/itembuy.php
10. Use sprintf to clean and trim all data.
11.  Secure and Re-name all staff_.php files, stick em in a folder and lock em up.
12.  Secure your crons to keep people from running them twice.


If you are unwilling or unable to do all of the above and then some,  Delete public_html and get a new hobby or hire a professional, that's what we're for :)

Hope that helps.

cheers

JanArve

  • Basic Member
  • *
  • Reputation Power: 3
  • JanArve has no influence.
  • Offline Offline
  • Posts: 7
    • View Profile
Re: mccodes v2 security
« Reply #5 on: November 09, 2009, 02:15:45 PM »
Thank you very much for that list!

And it does appear like I will never get enough time to actually secure the script myself, so if there are any guns for hire, feel free to PM me your quote for a full makeover on the basic script (If I do hire, I will most likly hire the same person again to go over the code another time when I've made the custom work on it, template and whatnot)
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #6 on: November 09, 2009, 02:40:17 PM »
Sadly the McCodes engine should have came with a warning label titled

All Files Insecure: Please secure yourself or have someone do this for you.  Sincerely --Da dumbstew.

JanArve

  • Basic Member
  • *
  • Reputation Power: 3
  • JanArve has no influence.
  • Offline Offline
  • Posts: 7
    • View Profile
Re: mccodes v2 security
« Reply #7 on: November 09, 2009, 02:50:55 PM »
I agree, had I known in advance the troubles involved in getting mccodes up and running I would have saved my money.

But as I have spent the money, and the script would be collecting dust anyways I would like to get a site running, but I do not care much for spending my time chasing cheaters and doing backups, so I'd rather spend some extra time (or dollars) to get it secure before I start.

Thanks for all that have replied and all those who have and will send me offer for securing the script.

Jan
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #8 on: November 09, 2009, 02:51:51 PM »
Yep, Pm sent, go over it :)

dominion

  • Active Member
  • **
  • Reputation Power: 89
  • dominion barely matters.dominion barely matters.
  • Offline Offline
  • Posts: 129
    • View Profile
    • Email
Re: mccodes v2 security
« Reply #9 on: November 09, 2009, 03:17:00 PM »
i was like this paid for a script and went away for a while due to family stuff come back 3 years later(i think) and it sucks lol thank fully i had some php back round did plan on paying someone cos i was lazy but did not work out to well i think when it came out php4 was the best php thing so mccodes was good and kind of secure just as time went on anyways as this is not helping heres a nice list of links

cmarket-
http://www.cronwerks.com/forum/cronwerks-free-mccode-mccodes-mods/(mccode)-secured-crystal-market/

forums
http://www.cronwerks.com/forum/cronwerks-free-mccode-mccodes-mods/(mccode)-secured-advanced-forums/

ip hack fic
http://www.cronwerks.com/forum/free-user-created-mccode-mccodes-mods/secure-the-$ip-variable-on-your-game/

there is one more link however i have never tested it and your always better off fixing every file
http://www.cronwerks.com/forum/free-user-created-mccode-mccodes-mods/anti-sql-injection-function/
Logged

dominion

  • Active Member
  • **
  • Reputation Power: 89
  • dominion barely matters.dominion barely matters.
  • Offline Offline
  • Posts: 129
    • View Profile
    • Email
Re: mccodes v2 security
« Reply #10 on: November 09, 2009, 03:19:30 PM »
o yea and go and look at peoples posts on mwg that you know can code lol no idea how long i looked at peoples codes picking up ideas i like php self now saves updateing links
« Last Edit: November 09, 2009, 03:32:23 PM by dominion »
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #11 on: November 09, 2009, 03:21:04 PM »
silly double poster you ;)


only thing that sucks about starting on this board is my post count is that of a nooby :|

Gonna have to change that ><

There is far to much to do to secure your game.  You can do basic fixes as stated, but there are reasons people like magictallguy charges in excess of 800.00 to secure an engine ;P

and even that isnt "full proof"

There's just no such thing.

dominion

  • Active Member
  • **
  • Reputation Power: 89
  • dominion barely matters.dominion barely matters.
  • Offline Offline
  • Posts: 129
    • View Profile
    • Email
Re: mccodes v2 security
« Reply #12 on: November 09, 2009, 03:34:36 PM »
silly double poster you ;)


only thing that sucks about starting on this board is my post count is that of a nooby :|

Gonna have to change that ><

There is far to much to do to secure your game.  You can do basic fixes as stated, but there are reasons people like magictallguy charges in excess of 800.00 to secure an engine ;P

and even that isnt "full proof"

There's just no such thing.

there i changed post 2 to something that may help lol (think i pressed f5 ::))
and nope but learning as you go can help but i dont think basic mccodes is good for that
Logged

JoshuaDams

  • Active Member
  • **
  • Reputation Power: 129
  • JoshuaDams is working their way up.JoshuaDams is working their way up.JoshuaDams is working their way up.
  • Offline Offline
  • Posts: 240
    • MSN Messenger - immortalthug4ever@hotmail.com
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #13 on: November 09, 2009, 03:37:00 PM »
Basic mccodes has more holes in it than swiss cheese :P

Danny696

  • Senior Member
  • ****
  • Reputation Power: 317
  • Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.Danny696 is a force to reckon with.
  • Offline Offline
  • Posts: 540
    • View Profile
    • WWW
Re: mccodes v2 security
« Reply #14 on: November 09, 2009, 03:44:49 PM »
Sprintf, doesnt not secure as much as you think, and will also slow down your script,
Logged
Project Choosen - 10%
Daniel - Hanson . Com
Pages: [1] 2
« previous next »
 


This forum is now closed and has moved to a new location! Click here to find out why.