Hello,
do you know any programm wich could test the security of my web site in local area? I don't find any... perhaps my key words are not precise enough... Any idea is welcome!
Thanks from advance!
web site security test
Started by dimitry, Jun 26 2009 06:44 AM
6 replies to this topic
#1
Posted 26 June 2009 - 06:44 AM
Lord Darkdriver by Dimitry
|
|
|
#2
Posted 26 June 2009 - 07:25 AM
I know there are security suites for checking for SQL Injection and other attacks. Search for "sql injection test suite" and you'll get a bunch of hits.
#3
Posted 26 June 2009 - 10:06 AM
I am sure if you posted your website a few of us could look at it. If you were even willing to post your source we might even take a quick look at it.
#4
Posted 29 June 2009 - 12:22 AM
Hello,
WingedPanther, your idea is good, I'll look with it.
BlaineSch, you're right, here you are!(in attachement)
bye.
WingedPanther, your idea is good, I'll look with it.
BlaineSch, you're right, here you are!(in attachement)
bye.
Attached Files
Edited by Jordan, 29 June 2009 - 11:39 AM.
Lord Darkdriver by Dimitry
#5
Posted 29 June 2009 - 06:07 AM
Yes its a huge security vulnerability to post your user/pass to your database!!! Remove that **** connection file now before you get screwed! and change your pass once your done!
#6
Posted 29 June 2009 - 06:12 AM
Is there a curse word filter on the forums? Odd I never saw that before..
I have been through a few of your files and yes your website is very very vulnerable. Here is a preview of what I have gotten so far. If you want more you will have to pay me. Or maybe some nice person will finish this off for you.
I have been through a few of your files and yes your website is very very vulnerable. Here is a preview of what I have gotten so far. If you want more you will have to pay me. Or maybe some nice person will finish this off for you.
Quote
Accueil.php
- Filter cookies input on line 7, 12, 13
- Even tho you are doing error checking on this - you should also keep track of how many you are sending per hour and probably limit it so you dont get somebody who is trying to crash your server. Probably justl ike a database row or a file or somethign that just keeps track of how many you send to limit it.
#7
Guest_Jordan_*
Posted 29 June 2009 - 11:39 AM
Guest_Jordan_*
I've removed the connect_db.php file.


Sign In
Create Account


Back to top











