Page 2 of 4
Re: MeLive chat
Posted: Mon Jan 24, 2011 8:08 pm
by mandai
huh? what is an eta
Estimated Time of Arrival (or release).
When I click change for the display picture then click cancel it says the path is not of a legal form.
Also it is quite unsecure using FTP for chat as anyone can edit the files in /htdocs/MeLive. I can also see Pass.txt
Re: MeLive chat
Posted: Mon Jan 24, 2011 8:51 pm
by M1z23R
Mandai, i forgot to ask you, can i secure my ftp or any other username and password that is in application by putting it in invisible textbox ?
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:00 pm
by kolega28
hey mandai don't look at the source it was for 1 person u basically hacked in to see the files don't do that please anyways I am gonna make a different ftp especially for that and I'm gonna make it extra-safe so far I just use code its
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:03 pm
by mandai
How is viewing a plaintext protocol considered hacking? I didn't look at the source.
And no, adding an invisible textbox won't make it secure.
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:15 pm
by GoodGuy17
Mandai, you viewed Pass.txt? Is that everyones' passwords? If so, that is hacking if you take accounts.
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:21 pm
by Axel
mandai wrote:How is viewing a plaintext protocol considered hacking? I didn't look at the source.
And no, adding an invisible textbox won't make it secure.
Open up with Reshacker and you've got it
GoodGuy17 wrote:Mandai, you viewed Pass.txt? Is that everyones' passwords? If so, that is hacking if you take accounts.
I wouldn't call that hacking but more 'Making profit of security holes' or 'troubleshooting' or 'bugtracking'
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:23 pm
by mandai
Who said anything about taking accounts?
Lol I've gotten used to my bugtracking role on this forum.
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:31 pm
by GoodGuy17
I never said you were taking them.
I said you shouldn't try to, because it would be hacking. (or more related, I suggested so)
Don't twist my words.
P.S. The way your last sentence sounds, makes it seem like you don't enjoy being here.
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:37 pm
by Axel
I don't even need to hack to get the credentials lol :P my antivirus will tell enough
Re: MeLive chat
Posted: Mon Jan 24, 2011 9:47 pm
by mandai
That last one was a joke in case you didn't get it.
My advice to make it secure would be to put a gateway like a server side script between the account data and the users.