Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,150,122 members, 7,807,398 topics. Date: Wednesday, 24 April 2024 at 01:06 PM

ALERT: Nairaland Declared Insecure | Loophole found - Programming (2) - Nairaland

Nairaland Forum / Science/Technology / Programming / ALERT: Nairaland Declared Insecure | Loophole found (5940 Views)

(2) (3) (4)

(1) (2) (Reply) (Go Down)

Re: ALERT: Nairaland Declared Insecure | Loophole found by Nobody: 3:09pm On Aug 22, 2017
Olyboy16:

normally i would be mad at you and reply you with heavy insults...but i won't, cos you're just a kid and being a child.
.
by the way i'm not your enemy either; that cms you're using is called question2answer written by scott.
the cms runs atleast 40 database queries on every question posted.
your site has atleast 50 deadly vulnerabilities, most of which exist in its core scripts e.g qa-user.php under your qa-include folder.
among the vulnerabilities is the ability to post a question without registeration or verification. several xss and post injection holes in the search script among others. also, some scripts in you qa-plugin/ domain are betraying you.
.
learn not to insult people on social media, especially when your full name and picture is available.
BTW kid, you only need a backdoor when you fear you may loose access!

All what you said isn't new to me, I am aware of all these vulnerabilities..q2a was the base of my development, forked for my purpose...most of the vulnerabilities known to me have been taken care of except some from 3rd party plugins I may not have knowledge of. If you found a bug just mail alert@friendosphere.com and it'll be fixed ASAP.
Besides I can boast of Rock solid security against majority of attacks which can land heavy blows on me....the connection is TLS encrypted over SSL and a TLS handshake is carried out before transferring data so it's almost impossible to sniff or steal data through a man-in-the-middle attack or through sniffing which is why you haven't been able to hack an account there yet, but keep trying tho...

About being rude, I'm sorry...mistook you for yahoofak... accept my apologies.
Re: ALERT: Nairaland Declared Insecure | Loophole found by Nobody: 5:19pm On Aug 22, 2017
In fact I will give N20,000 to anyone that can post a question on FriendoSphere without registering under 3 days.

Drop the question link here with pictoral proof of the attack and your account number... I'm up for the security challenge.
Re: ALERT: Nairaland Declared Insecure | Loophole found by Nobody: 6:21pm On Aug 22, 2017
Topkonsult24:
Easy, Fast Way to Grow Target Audience

Hello, my name is Melody, I'm part of the team at www.AMAfeed.com
I want to invite you to Host an AMA to promote your business,site e.t.c. We have one of the fastest growing platforms on the web right now, and it is absolutely free! Since our launch in May this year we have gained an incredible user base of 20 000 people and have over 50 000 hits on the site daily.

Presently we are looking for experienced individuals with inspiring stories to share their knowledge with our audience.

Looking for a way to increase your social exposure? Want an outlet to express yourself, advertise your blog, products, and talents? Looking for a way to raise money? This is the platform for you! We will also assist you with all you need as to getting your desired audience on our platform.
An AMA provides you the platform to directly interact with others, in a Q&A setting. You are the host!

Thank you for your time and I am looking forward to having you as one of our hosts. Feel free to look around the site https://amafeed.com/?partner=1921 and don’t hesitate to contact me if you need any assistance.

Kind regards
Melody
AMAfeeds
I wouldn't have appreciated an attempt to hijack the thread but your post actually caught my attention. Hope you don't mind sharing more info about your platform, maybe through Skype or PM..
Re: ALERT: Nairaland Declared Insecure | Loophole found by Olyboy16(m): 6:23pm On Aug 22, 2017
DanielTheGeek:


All what you said isn't new to me, I am aware of all these vulnerabilities..q2a was the base of my development, forked for my purpose...most of the vulnerabilities known to me have been taken care of except some from 3rd party plugins I may not have knowledge of..
Besides I can boast of Rock solid security against majority of attacks which can land heavy blows on me....the connection is TLS encrypted over SSL and a TLS handshake is carried out before transferring data so it's almost impossible to sniff or steal data through a man-in-the-middle attack or through sniffing which is why you haven't been able to hack an account there yet, but keep trying tho...

About being rude, I'm sorry...mistook you for yahoofak... accept my apologies.
tsk tsk tsk, u just dont get it! injection vulnerabilities have nothing to do with secured connection or MITM attacks. i guess u nid to go back to your ebooks daniel
.
BTW, your apologies meets me well. thank you.
Re: ALERT: Nairaland Declared Insecure | Loophole found by Nobody: 7:08pm On Aug 22, 2017
Olyboy16:

tsk tsk tsk, u just dont get it! injection vulnerabilities have nothing to do with secured connection or MITM attacks. i guess u nid to go back to your ebooks daniel
.
BTW, your apologies meets me well. thank you.

I understand you bro, I was just trying to point out that the attack is non-authoritative and mostly a spamming technique to users that may be reading this thread, I could have lost users based on the thought that the site isn't secure, but even at that I am very confident a question cannot be posted without registering (and even email confirmation) until someone proves me wrong.

Do Have a good day man.
Re: ALERT: Nairaland Declared Insecure | Loophole found by agwaisrael(m): 10:04pm On Aug 22, 2017
Quick question! Tls I know secures network connections so how can you read the packets from your local machine?
Re: ALERT: Nairaland Declared Insecure | Loophole found by JayJayGee: 2:57am On Sep 21, 2021


Awesome, what I've been waiting for since!
Give me some time. Away from my PC at the moment. Will be back, If successful I will post with your account on this board saying "DanielTheGeek hacked me"
How far this guy? This is 2021 and he never still hack the account grin
Re: ALERT: Nairaland Declared Insecure | Loophole found by Bigshoe2028: 4:47am On Sep 21, 2021
Noise makers he can't even hack his modem, 4years he still never reach where his computer dey

1 Like

Re: ALERT: Nairaland Declared Insecure | Loophole found by nnamdiosu(m): 5:13am On Sep 23, 2021
Bigshoe2028:
Noise makers he can't even hack his modem, 4years he still never reach where his computer dey

Lol smiley

(1) (2) (Reply)

Creating A Proxy Server With Java. / Tutorial: How To Return Html In Json Response Using Asp.net And Jquery / I Want To Be Developing .jar Aps For Nokia Phones. Where Do I Start?developing .jar Mobile Apps What

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 24
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.