We hope you enjoy your visit.

You're currently viewing our forum as a guest. This means you are limited to certain areas of the board and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free.


Join our community!


If you're already a member please log in to your account to access all of our features:

Username:   Password:
Add Reply
  • Pages:
  • 1
  • 3
IF is NOT HACKABLE!
Topic Started: May 11 2005, 08:58 PM (1,873 Views)
Paper
Member Avatar
Member
[ *  *  *  *  *  * ]
Quote:
 
My friend claims his friends board has hacked through MySQL, and not cracked. I said this was impossible, but he said you can hack IF through PHPMyAdmin. He doesn't seem to understand you cannot hack IF, and I need people to post here saying that so I can show him this

Firstly, IF does use PHP. And no, you can't run your PHP scripts using their server, but you might be able exploit scripts that the boards use. If Duffman uses PHPMyAdmin, then, again, there could be exploits in the scripts.

Secondly, it also uses MySQL. Whilst you might not be able to access it, there are again, exploits.

Lastly, it would be slow, unless you could predict what to do based on a few results from a query.

Saying something can’t be hacked is ignorant. It's like putting loads of locks on your doors, locking your windows, and saying, "No one can break into my home." But wait, they could smash the window. But, you didn’t think of that.

The same situation applies here. There might be something Duffman missed. Unless people report their hacking attempts, no one will ever know. Since the TOS forbids it, and people fear prosecution, it is unlikely that they will report it.

Organisations like PHPBB allow exploits to be reported. It’s silly not to allow people to report exploits. If someone does hack and they don’t report it due to a rule, then what is the point of that rule? It obviously hasn’t stopped them.
Offline Profile Quote Post Goto Top
 
SargeTron
Unregistered

Paper1
May 14, 2005 11:24 AM
Quote:
 
My friend claims his friends board has hacked through MySQL, and not cracked. I said this was impossible, but he said you can hack IF through PHPMyAdmin. He doesn't seem to understand you cannot hack IF, and I need people to post here saying that so I can show him this

Firstly, IF does use PHP. And no, you can't run your PHP scripts using their server, but you might be able exploit scripts that the boards use. If Duffman uses PHPMyAdmin, then, again, there could be exploits in the scripts.

Secondly, it also uses MySQL. Whilst you might not be able to access it, there are again, exploits.

Lastly, it would be slow, unless you could predict what to do based on a few results from a query.

Saying something can’t be hacked is ignorant. It's like putting loads of locks on your doors, locking your windows, and saying, "No one can break into my home." But wait, they could smash the window. But, you didn’t think of that.

The same situation applies here. There might be something Duffman missed. Unless people report their hacking attempts, no one will ever know. Since the TOS forbids it, and people fear prosecution, it is unlikely that they will report it.

Organisations like PHPBB allow exploits to be reported. It’s silly not to allow people to report exploits. If someone does hack and they don’t report it due to a rule, then what is the point of that rule? It obviously hasn’t stopped them.

To that extent: if IF gets a spare server that isn't very valuable, REAL hackers (not crackers) could try out their hand at hacking it then being able to report it to Duffman. That'd be good.
Quote Post Goto Top
 
Zero Resistance-ZNS
eÜil Zero lÖrd™
[ *  *  *  * ]
SargeTron
May 14, 2005 11:46 AM
Paper1
May 14, 2005 11:24 AM
Quote:
 
My friend claims his friends board has hacked through MySQL, and not cracked. I said this was impossible, but he said you can hack IF through PHPMyAdmin. He doesn't seem to understand you cannot hack IF, and I need people to post here saying that so I can show him this

Firstly, IF does use PHP. And no, you can't run your PHP scripts using their server, but you might be able exploit scripts that the boards use. If Duffman uses PHPMyAdmin, then, again, there could be exploits in the scripts.

Secondly, it also uses MySQL. Whilst you might not be able to access it, there are again, exploits.

Lastly, it would be slow, unless you could predict what to do based on a few results from a query.

Saying something can’t be hacked is ignorant. It's like putting loads of locks on your doors, locking your windows, and saying, "No one can break into my home." But wait, they could smash the window. But, you didn’t think of that.

The same situation applies here. There might be something Duffman missed. Unless people report their hacking attempts, no one will ever know. Since the TOS forbids it, and people fear prosecution, it is unlikely that they will report it.

Organisations like PHPBB allow exploits to be reported. It’s silly not to allow people to report exploits. If someone does hack and they don’t report it due to a rule, then what is the point of that rule? It obviously hasn’t stopped them.

To that extent: if IF gets a spare server that isn't very valuable, REAL hackers (not crackers) could try out their hand at hacking it then being able to report it to Duffman. That'd be good.

That could be a waste of money.

Plus, Hockers can back stab dufman and hack the real servers.

so, unless IF staff do it, and not experienced hackers...

well, you get it. :ermm:
Offline Profile Quote Post Goto Top
 
Jory
Member Avatar
Member
[ *  *  *  *  *  * ]
So then they'd need somebody in the staff that is an experienced hacker :rolleyes:
(But there might already be, who (exept from staff itself) knows?)

Offline Profile Quote Post Goto Top
 
RagingFuryBlack-ZNS
Member
[ *  *  * ]
Qj
May 16, 2005 04:57 AM
So then they'd need somebody in the staff that is an experienced hacker :rolleyes:
(But there might already be, who (exept from staff itself) knows?)

im sure duff and or seth could do dammage if they wished to turn their attention to the hacking/cracking world. They are both experienced coders...and i bet could do some real dammage if left alone for awhile


Not like they'd ever want to or anything :angel:
Offline Profile Quote Post Goto Top
 
Seth
Member Avatar
I has a pony
[ *  *  *  *  *  *  *  *  * ]
One member of our staff actually discovered how it was possible to completely destroy every board on one of our competitors. Of course we did not :P I believe we are in the process of informing the company on how to fix the problem.
Offline Profile Quote Post Goto Top
 
hatefulemperor17-ZNS
Because I can.
[ *  *  * ]
Seth
May 16, 2005 03:24 PM
One member of our staff actually discovered how it was possible to completely destroy every board on one of our competitors. Of course we did not :P I believe we are in the process of informing the company on how to fix the problem.

Thats very nice of you guys :yes:
Offline Profile Quote Post Goto Top
 
RagingFuryBlack-ZNS
Member
[ *  *  * ]
Seth
May 16, 2005 03:24 PM
One member of our staff actually discovered how it was possible to completely destroy every board on one of our competitors. Of course we did not :P I believe we are in the process of informing the company on how to fix the problem.

*RagingFuryBlack pokes seth for said compedetor and exploit :angel:
Offline Profile Quote Post Goto Top
 
Zero Resistance-ZNS
eÜil Zero lÖrd™
[ *  *  *  * ]
Seth
May 16, 2005 03:24 PM
One member of our staff actually discovered how it was possible to completely destroy every board on one of our competitors. Of course we did not :P I believe we are in the process of informing the company on how to fix the problem.

Why? Without the competitor, you could have been supreme.

was it proboards?
Offline Profile Quote Post Goto Top
 
1 user reading this topic (1 Guest and 0 Anonymous)
« Previous Topic · zIFBoards Discussion · Next Topic »
Add Reply
  • Pages:
  • 1
  • 3