if you do ?admin it didn't stop blind code. &admin is another way to see selection from database failed.
Zhen-Xjell Nuke Cops Founder
Joined: Nov 14, 2002
Posts: 5939
Posted:
Wed May 26, 2004 7:44 pm
One cannot access admin.php unless its the first parameter called after the ?. The &admin is not the actual file called, which is what I'm really after.
_________________ Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
xfsunolesphp Lieutenant
Joined: Apr 05, 2003
Posts: 208
Location: Melbourne, FL
Posted:
Wed May 26, 2004 7:53 pm
can you try &admin?
marcoledingue Captain
Joined: Jun 15, 2003
Posts: 322
Location: Paris, FRANCE
Posted:
Thu May 27, 2004 12:58 am
i can confirm that the &admin protection is usefull !
i've seen a hacker using this.
it's not to accesss admin.php, but to fake the admin cookie-variable.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum