![]() |
Rename adoptables (Security issue fixed!)
Update: I fixed the "hacking" security issue, I think.
Step 1: Download rename.php and rename2.php and put them in your main folder. Step 2: Add this link <a href='rename.php?id=$id'>Rename ".$name."</a> to myadoptables.php. Here is an example: Find this line with ctrl + f. PHP Code:
PHP Code:
Now the pages have been updated to display general messages. |
RE: Rename adoptables (because we REALLY can't wait)
iluvu =)
|
RE: Rename adoptables (because we REALLY can't wait)
i now have it
|
RE: Rename adoptables (because we REALLY can't wait)
wow, thanks again for a great mod kisazeky :) , but where exactly do i add "rename.php?id=$id" ??
Can you help us all out with the shop mod though please ?? no-one can get it working :( |
RE: Rename adoptables (because we REALLY can't wait)
OH MY GOSH. You are officially a genius ><
|
RE: Rename adoptables (because we REALLY can't wait)
rosepose, if you got it working, can you tell me where you added the link "rename.php?id=$id" please ??
|
RE: Rename adoptables (because we REALLY can't wait)
In rename.php
Some of you might wanna change this... PHP Code:
|
RE: Rename adoptables (because we REALLY can't wait)
D'oh! Sorry. I changed it to display general messages.
|
RE: Rename adoptables (Updated!!)
The link you say to add doesnt work, you need to add it like this :
<a href='rename.php?id=".$id."&action=rename'>Click Here to rename ".$name.".</a> <br> |
RE: Rename adoptables (Updated!!)
You sir, are a genius!
EDIT: It works fine on my site, just the way it is, So maybe you didn't have something right in your script page? |
RE: Rename adoptables (Updated!!)
*****CAUTION********
I used this today.. worked great.. went out, .. came home.., GREY SCREEN!! I call my host for that site & asked.. they found a hack entry from the script!! They fixed the issue on ALL pages & emailed me some info on protection. I will read the email in the morning & give for info. But there is a security issue in the mod. Sea |
RE: Rename adoptables (Updated!!)
It doesnt filter for SQL injections i bet...
|
RE: Rename adoptables (Updated!!)
I included this
PHP Code:
Edit: Maybe this will protect it? Adding this to functions.php: PHP Code:
PHP Code:
What do you think Rsmiley? It certainly does not hurt anything. |
RE: Rename adoptables (Updated!!)
It should be quite secure. I doubt it would be exploitable after that has been added.
You are safe with that added |
RE: Rename adoptables (Updated!!)
Quote:
PHP Code:
Code:
$newname = $_POST["newname"]; PHP Error Message Parse error: syntax error, unexpected T_IF in /home/---------/public_html/rename2.php on line 78 Free Web Hosting" |
RE: Rename adoptables (Updated!!)
No, don't do that.
Add PHP Code:
PHP Code:
|
RE: Rename adoptables (Security issue fixed!)
^
All done, thanks =) |
RE: Rename adoptables (Security issue fixed!)
Cool :) Thanks for the fix
:) Sea ***EDIT*** **FYI** This is an edit just because I do tend to hear things. I have just heard a rumor that Soleria stole code, just because they used this script without changing the Digimon reference. I corrected the person before they took this rumor further, but that is how easy rumors can start in this field. So please make sure you offer generic scripts & those using the scripts make sure you check them for issues like this. Sea |
RE: Rename adoptables (Security issue fixed!)
Yes I did change this to be more generic.
|
RE: Rename adoptables (Security issue fixed!)
I'm sorry Kisazeky, when I said "you" I really didn't mean YOU. I know you had made the change to be more generic. :) I was just meaning "you" in general to anyone who might offer a script or design so that some unsuspecting site didn't get in trouble for something they didn't do. :)
Sea |
RE: Rename adoptables (Security issue fixed!)
Nice, but...
...when the box with the name is blank... ...and accepted an empty name... ...Pet will have a bug. You will not be able to see the his card. My proposal: When the box is left blank, the name will not change. |
RE: Rename adoptables (Security issue fixed!)
great idea ... thanks
|
RE: Rename adoptables (Security issue fixed!)
It aswell works accomplished and no problems or errors was found. Thanks.
_________________ Adt security |
RE: Rename adoptables (Security issue fixed!)
You are greatly a genius! By the way, thanks for sharing those steps. I know that you will do more post having an informative message. I am looking forward to it. Thanks a lot!
_________________ Indianapolis Dentist |
All times are GMT -5. The time now is 03:33 AM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.