| We hope you enjoy your visit. You're currently viewing our forum as a guest. This means you are limited to certain areas of the board and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free. Join our community! If you're already a member please log in to your account to access all of our features: |
| IMPORTANT | |
|---|---|
| Tweet Topic Started: Feb 5 2005, 04:16 PM (1,918 Views) | |
| RedKrazyKid | Feb 5 2005, 04:16 PM Post #1 |
|
Member
![]() ![]() ![]() ![]() ![]()
|
You can change the look of the admin cp, and change everything about it just by knowing the location of the admin cp and using a hack program to find passwords. I just had to do this to myself so I could access my admin cp because I accidentally made all the stuff dissappear on the main page by typing in "</textarea></form><style>". (I was curious) So I opened up acehtmlpro and opened the file from web address. I edited the code so that the text I typed in was out of the textbox, and low and behold, my admin cp works. This seems to me to be very crucial. You can ruin the entire admin cp just by knowing the url to the index admin cp. That's not too safe in my opinion. Is anything going to be done about this? If you'd like a better example, type in what i typed in in your admin cp notepad. Then open up your html editing program and you will see that you can edit it without being in the admic cp. Without even having the needed cookies. You just need the adsess link. It would be hard to guess the numbers, but is possible, and easy for a pro... I guess you could call it. So what's going to happen about this? |
![]() |
|
| Lothlómendil | Feb 5 2005, 04:19 PM Post #2 |
|
Spam Queen
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
It is known that you can enter the ACP just by having the session URL. This is why we have this topic posted: http://support.invisionfree.com/index.php?showtopic=12994 Edit: perhaps I posted the wrong link, just a sec... http://invisionfree.com/index.php?p=art_sec |
![]() |
|
| RedKrazyKid | Feb 5 2005, 04:20 PM Post #3 |
|
Member
![]() ![]() ![]() ![]() ![]()
|
Is it safe to manipulate the textbox in order to make the main page have a style different than default? |
![]() |
|
| RedKrazyKid | Feb 5 2005, 04:25 PM Post #4 |
|
Member
![]() ![]() ![]() ![]() ![]()
|
I also just added a few working buttons on my acp main page. I added links too. What I'm doing, is it safe? |
![]() |
|
| RedKrazyKid | Feb 5 2005, 04:28 PM Post #5 |
|
Member
![]() ![]() ![]() ![]() ![]()
|
Thanks. Ooh! I can change the text of the button you click to save the notepad changes too. This rocks.
|
![]() |
|
| Gogf | Feb 5 2005, 04:49 PM Post #6 |
|
Indescribable
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Honestly, I have no idea what you're talking about, but I really suggest that you if it enables you to accept the Admin CP without using your password, that you change it back immediately. Messing around with the Admin CP is a very dangerous game, no matter how good you are. One mistake, and... poof! No more Admin CP. |
![]() |
|
| kevkev44 | Feb 5 2005, 04:51 PM Post #7 |
|
sucka free sundays
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
But there is the Support Ticket right? |
![]() |
|
| Lothlómendil | Feb 5 2005, 04:52 PM Post #8 |
|
Spam Queen
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Messing up the ACP by changing things using this method is easily fixed. Just edit it again. |
![]() |
|
| doug05257-ZNS | Feb 5 2005, 05:00 PM Post #9 |
|
http://www.gepforum.com
![]() ![]() ![]() ![]()
|
Still, there are hackers... |
![]() |
|
| Dynasty | Feb 5 2005, 08:01 PM Post #10 |
|
Senior Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Modifying the ACP, isnt that against the TOS? |
![]() |
|
| Seth | Feb 5 2005, 08:07 PM Post #11 |
|
I has a pony
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Nope. His ACP, he can do what he wants. |
![]() |
|
| BikersForums | Feb 5 2005, 08:39 PM Post #12 |
|
Member
![]() ![]() ![]() ![]()
|
can you realy mayb i should hack it a bit then.. (myn)EDIT,oopsy... i deleted somthin out of admin cp ![]() EDIt, fixed it
|
![]() |
|
| BikersForums | Feb 5 2005, 08:45 PM Post #13 |
|
Member
![]() ![]() ![]() ![]()
|
i did that once with anuthor board of mine
|
![]() |
|
| dbzlotrfan | Feb 5 2005, 08:51 PM Post #14 |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
dont' think you could actually do anything, because wouldn't you have to FTP them to the ACP? and IF doesn't offer FTP. <_>_< |
![]() |
|
| Gogf | Feb 5 2005, 08:53 PM Post #15 |
|
Indescribable
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
My question is what exactly is he editing? Where is he closing this textbox? What is he editing with "acehtmlpro"? How can he edit something on the board without a password? Sounds like a security risk. |
![]() |
|
| 1 user reading this topic (1 Guest and 0 Anonymous) | |
| Go to Next Page | |
| « Previous Topic · zIFBoards Discussion · Next Topic » |
| Track Topic · E-mail Topic |
11:33 AM Jul 11
|



![]](../../../../0/1/0/p601690/pipright.png)



This rocks.
mayb i should hack it a bit then.. (myn)
11:33 AM Jul 11