Community
Bowhunting Talk about the passion that is bowhunting. Share in the stories, pictures, tips, tactics and learn how to be a better bowhunter.

[Deleted]

Thread Tools
 
Old 02-19-2008, 06:57 PM
  #21  
Boone & Crockett
 
Germ's Avatar
 
Join Date: Sep 2005
Location: Michigan/Ohio
Posts: 11,682
Default RE: [Deleted]

ORIGINAL: MN/Kyle

ORIGINAL: Germ

ORIGINAL: KansasBBD

What do you do, just Block the IP address?
It's not that easy to block IP's. The developers of thi site need to do most of the work. I have yet to be on when it happens, but do to the volume my guess is they are running java scripts on the server.

So when a legitment user post, it triggers a script that runs and creates all these bogus post.
Sounds like some people have too much time on thier hands?? Glad it's all fixed.
I should show you some things people try to do on our sites. They will try anything to get in. It's user inputs that are easiest to use.

HNI is all user inputs(parameters). Adding a program in a search box that runs on a server. I do not want to show an example, I am sure Justin would skin me alive
Germ is offline  
Old 02-19-2008, 06:58 PM
  #22  
neb
Typical Buck
 
Join Date: Dec 2005
Location: MT
Posts: 763
Default RE: Hey come the hacker antis' !!

Has this happened before on this forum. This is a bad thing.
neb is offline  
Old 02-19-2008, 07:01 PM
  #23  
Nontypical Buck
 
buckmaster's Avatar
 
Join Date: Jul 2007
Location: Virginia
Posts: 3,882
Default RE: Hey come the hacker antis' !!

Germs a Computer nerd! ( i might pay for that one.... I gotta go check my bank account...[])
buckmaster is offline  
Old 02-19-2008, 07:02 PM
  #24  
Nontypical Buck
 
MN/Kyle's Avatar
 
Join Date: Mar 2007
Location: Minnesota
Posts: 4,911
Default RE: [Deleted]

ORIGINAL: Germ
I should show you some things people try to do on our sites. They will try anything to get in. It's user inputs that are easiest to use.

HNI is all user inputs(parameters). Adding a program in a search box that runs on a server. I do not want to show an example, I am sure Justin would skin me alive
Germ, have you ever thought about becoming a college professor? I have a "Computers in society"class this semester and it flys over my head, what you said makes sense.
MN/Kyle is offline  
Old 02-19-2008, 07:08 PM
  #25  
Boone & Crockett
 
Germ's Avatar
 
Join Date: Sep 2005
Location: Michigan/Ohio
Posts: 11,682
Default RE: [Deleted]

ORIGINAL: MN/Kyle

ORIGINAL: Germ
I should show you some things people try to do on our sites. They will try anything to get in. It's user inputs that are easiest to use.

HNI is all user inputs(parameters). Adding a program in a search box that runs on a server. I do not want to show an example, I am sure Justin would skin me alive
Germ, have you ever thought about becoming a college professor? I have a "Computers in society"class this semester and it flys over my head, what you said makes sense.
Every boss I have had describes me as a Nerd without being a Nerd. Yes I talk plain english without all the buzz words. I try to keep it simple.


Germ is offline  
Old 02-19-2008, 07:15 PM
  #26  
Boone & Crockett
 
Germ's Avatar
 
Join Date: Sep 2005
Location: Michigan/Ohio
Posts: 11,682
Default RE: [Deleted]

Yep without a doubt it's XSS attack or SQL Injection.They have found a way in.

It could be SQL Injection also. HNI needs to run everything in Store Procedures and have parameters defined(size) to stop this.
Ifsomeone is running SQL command in strings inside code, well it's very bad practice. These strings can have commands "Added" on.

Germ is offline  
Old 02-19-2008, 07:17 PM
  #27  
Nontypical Buck
 
buckmaster's Avatar
 
Join Date: Jul 2007
Location: Virginia
Posts: 3,882
Default RE: [Deleted]

DO SOMETHING GERM!!
buckmaster is offline  
Old 02-19-2008, 07:21 PM
  #28  
Nontypical Buck
 
MOhunter46's Avatar
 
Join Date: Oct 2007
Location: Warsaw,MO
Posts: 2,046
Default RE: [Deleted]

ORIGINAL: buckmaster

DO SOMETHING GERM!!
Ya,get em Germ!!
MOhunter46 is offline  
Old 02-19-2008, 07:28 PM
  #29  
Typical Buck
 
KansasBBD's Avatar
 
Join Date: Oct 2007
Location: Kansas baby!
Posts: 708
Default RE: [Deleted]

ORIGINAL: Germ

Yep without a doubt it's XSS attack or SQL Injection.They have found a way in.

It could be SQL Injection also. HNI needs to run everything in Store Procedures and have parameters defined(size) to stop this.
Ifsomeone is running SQL command in strings inside code, well it's very bad practice. These strings can have commands "Added" on.
Germ for moderator 08'
KansasBBD is offline  
Old 02-19-2008, 07:29 PM
  #30  
Boone & Crockett
 
Germ's Avatar
 
Join Date: Sep 2005
Location: Michigan/Ohio
Posts: 11,682
Default RE: [Deleted]

I can't, LOL

If I was HNI first thing I would do is take all the SQL statements out of code and use Store Procedures with Paramters. You can set the size of your user input parameters and stop injections.

Guys a moderator/admin cannot fix this, it has to be a developer. It's not HNI fault, it's bad coding practices.
Germ is offline  


Quick Reply: [Deleted]


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.