You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 61 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - SQL Injection?!?!? [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
foxyfemfem
Support Staff
Support Staff


Joined: Jan 23, 2003
Posts: 668

Location: USA

PostPosted: Wed Apr 02, 2003 12:10 pm Reply with quoteBack to top

Hello,

I've read several of the nuke security posts. Could someone please take 5 minutes or however long it may take to explain to me what is this sql injection stuff and how can I stop it from happening to me again? Is there a file or something I can store inside my database to stop the injection?

I'd like to feel secure and I definitely would like to make sure my members personal data is secure.

I have a privacy policy statement on my website and I'd like to live up to it by making sure all of my members information is secure.

I feel if they can tap into my sql database to screw up my website, I think they could retrieve personal information concerning my members as well.

I'd truly appreciate any insight one may have to help stop this madness from happening again.
Find all posts by foxyfemfemView user's profileSend private message
ArtificialIntel



Joined: Jan 31, 2004
Posts: -88


PostPosted: Wed Apr 02, 2003 12:17 pm Reply with quoteBack to top

an SQL injection is basically when a wannabe hacker (they don't deserve the honorable title of hacker) uses a program that takes a URL on a site, and makes changes to an SQL database using that URL.

If you've applied all the security patches for Nuke 6.5, (they might have been included in the release that was available to the public today by default) then your stories should be ok.

There's 1 other little possible security problem that we're working on a solution to, but for now, simply disabling comments in stories, or restricting them to members only should do the trick.

AI
Find all posts by ArtificialIntelView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.178 Seconds - 343 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::