Naruto Shippuden

Naruto Discussion Forum
Who should win? Be sure to nominate who will reign supreme for this month's Member of the Month!

Go Back   Naruto Discussion Forum > Leaf Police Force HQ > Feedback Forum

Feedback Forum Have any opinions or suggestions for us about the site? Post them here.

Closed Thread
 
Thread Tools
Old 11-12-2010, 08:44 PM   #1
Rikudo Sennin
7-Up Disciple
 
Rikudo Sennin's Avatar
 
Join Date: Dec 2009
Location: Me Want Negative Reps
Posts: 3,678
Rep Power: 8
Rikudo Sennin has completed a tough C-rank mission!Rikudo Sennin has completed a tough C-rank mission!
Default Increase the Forum's Security

It seems this Forum is still vulnerable to hacking, threads like this is an example:

http://naruto.viz.com/forum/showthread.php?t=70755

I think its about time for the Staff to increase the Security of this forum (or even the main site) before something happens.

I made a research, and performed some experiments and to my shock the Forum is vulnerable (.. What if hackers attack w/ the Officials offline?. Its gonna be a byebye for the site/forum.

Previous Experiment of Mine Result:
Spoiler:
Target Information
Target http://naruto.viz.com:80/forum/
Server banner Apache/2.2.4 (Ubuntu) PHP/5.2.3-1ubuntu6.5
Operating system Unix
Web server Apache 2.x
Technologies PHP

SSL 2.0 deprecated protocol
Vulnerability description
The remote service encrypts traffic using an old deprecated protocol with known weaknesses.
Affected items
Server
The impact of this vulnerability
An attacker may be able to exploit these issues to conduct man-in-the-middle attacks or decrypt communications between the affected service and clients.

also.

Insecure crossdomain.xml
Vulnerability description
The browser security model normally prevents web content from one domain from accessing data from another domain. This is commonly known as the "same origin policy". URL policy files grant cross-domain permissions for reading data. They permit operations that are not permitted by default. The URL policy file is located, by default, in the root directory of the target server, with the name crossdomain.xml (for example, at http://www.example.com/crossdomain.xml).

When a domain is specified in crossdomain.xml file, the site declares that it is willing to allow the operators of any servers in that domain to obtain any document on the server where the policy file resides. The crossdomain.xml file deployed on this website opens the server to all domains (use of a single asterisk "*" as a pure wildcard is supported) like so:
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
This practice is suitable for public servers, but should not be used for sites located behind a firewall because it could permit access to protected areas. It should not be used for sites that require authentication in the form of passwords or cookies. Sites that use the common practice of authentication based on cookies to access private or user-specific data should be especially careful when using cross-domain policy files.
Affected items
Server
The impact of this vulnerability
Using an insecure cross-domain policy file could expose your site to various attacks.


Let us not take this for granted.
__________________


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Feed me some negative reps
no reverse psychology please

Do.not.be.Afraid

Last edited by Rikudo Sennin; 11-12-2010 at 09:03 PM.
Rikudo Sennin is offline  
Old 11-12-2010, 08:47 PM   #2
Nick Tasogare
Special Jonin Candidate
 
Nick Tasogare's Avatar
 
Join Date: Apr 2009
Location: Getting at you where you live.
Posts: 27,570
Rep Power: 20
Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.
Send a message via Skype™ to Nick Tasogare
Default Re: Increase the Forum's Security

LOLOLOLOLOLOL

/Dies from inability to breathe
__________________
Was on to check PMs and read about the drama and got hit with the forums rules.

Can Herr SRhyse and Frau Muffintop please remove my staff "powers"? The Mod Rules are a joke and everybody knows it lol I don't follow that last rule well enough, and I don't want to endanger the Communist Rule of the People's Republic of NDF. Thanks.

/Heil

Oh wait, now there's drama so I just have to watch this all blow up.
Nick Tasogare is offline  
Old 11-12-2010, 08:48 PM   #3
Ryuuko
Bishyhoar
 
Ryuuko's Avatar
 
Join Date: Jan 2010
Posts: 11,027
Rep Power: 14
Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.Ryuuko completed an A-Rank mission and saved the forum yet again.
Default Re: Increase the Forum's Security

....Wow
__________________
Ain't no such things as halfway crooks

Spoiler:

Quote:
Are you doing your R. Kellsey impression again? >.>
Quote:
With enough liquor you could fool yourself into thinking you are a samurai. Then you've won twice.
Quote:
I miss you and beating up creepers for you.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Quote:
Yes 30. Might as well kill yourself first.
Quote:
Ryuuko, I am bottomless without yoouuu.
Ryuuko is offline  
Old 11-12-2010, 08:49 PM   #4
Rikudo Sennin
7-Up Disciple
 
Rikudo Sennin's Avatar
 
Join Date: Dec 2009
Location: Me Want Negative Reps
Posts: 3,678
Rep Power: 8
Rikudo Sennin has completed a tough C-rank mission!Rikudo Sennin has completed a tough C-rank mission!
Default Re: Increase the Forum's Security

Quote:
Originally Posted by Nick Tasogare View Post
LOLOLOLOLOLOL

/Dies from inability to breathe
I am confused right now, anyway
is it okay for me to post the vulnerability details??

Quote:
Originally Posted by Ryuuko View Post
....Wow
huh ?
__________________


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Feed me some negative reps
no reverse psychology please

Do.not.be.Afraid
Rikudo Sennin is offline  
Old 11-12-2010, 08:53 PM   #5
Blind Uchiha
formerly Kuroi Kagai
Lightning Amp Disciple
Justice of the BG
Moderator
 
Blind Uchiha's Avatar
 
Join Date: Aug 2009
Location: Virtual Reality
Posts: 4,657
Rep Power: 14
Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.Blind Uchiha strikes fear and awe in the fragile hearts of Genins.
Send a message via Skype™ to Blind Uchiha
Default Re: Increase the Forum's Security

Th3r3 b3 h4x tr0uble on teh f0rum.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Blind Uchiha is offline  
Old 11-12-2010, 08:55 PM   #6
TheBlackChidori
Special Jonin Candidate
 
TheBlackChidori's Avatar
 
Join Date: Apr 2009
Location: Wherever the Winds of Fate take me.
Posts: 14,869
Rep Power: 0
TheBlackChidori is just chillin' in the village doing D-ranks at this point
Default Re: Increase the Forum's Security

Rest....Rest assured, the forum is safe and secure. Any past instances....have been well taken care of... >_>
TheBlackChidori is offline  
Old 11-12-2010, 08:56 PM   #7
Rikudo Sennin
7-Up Disciple
 
Rikudo Sennin's Avatar
 
Join Date: Dec 2009
Location: Me Want Negative Reps
Posts: 3,678
Rep Power: 8
Rikudo Sennin has completed a tough C-rank mission!Rikudo Sennin has completed a tough C-rank mission!
Default Re: Increase the Forum's Security

Quote:
Originally Posted by Blind Uchiha View Post
Th3r3 b3 h4x tr0uble on teh f0rum.
!(\/) 4(7l_l411j 5312!0l_l5 '130l_l7 7#!5...
(Im actually serious 'bout this)

EDIT:

Quote:
Originally Posted by TheBlackChidori View Post
Rest....Rest assured, the forum is safe and secure. Any past instances....have been well taken care of... >_>
Well I do hope this is real.
__________________


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Feed me some negative reps
no reverse psychology please

Do.not.be.Afraid
Rikudo Sennin is offline  
Old 11-12-2010, 08:59 PM   #8
Nick Tasogare
Special Jonin Candidate
 
Nick Tasogare's Avatar
 
Join Date: Apr 2009
Location: Getting at you where you live.
Posts: 27,570
Rep Power: 20
Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.
Send a message via Skype™ to Nick Tasogare
Default Re: Increase the Forum's Security

STOP IT I'M GONNA SUFFOCATE!
__________________
Was on to check PMs and read about the drama and got hit with the forums rules.

Can Herr SRhyse and Frau Muffintop please remove my staff "powers"? The Mod Rules are a joke and everybody knows it lol I don't follow that last rule well enough, and I don't want to endanger the Communist Rule of the People's Republic of NDF. Thanks.

/Heil

Oh wait, now there's drama so I just have to watch this all blow up.
Nick Tasogare is offline  
Old 11-12-2010, 09:02 PM   #9
Rikudo Sennin
7-Up Disciple
 
Rikudo Sennin's Avatar
 
Join Date: Dec 2009
Location: Me Want Negative Reps
Posts: 3,678
Rep Power: 8
Rikudo Sennin has completed a tough C-rank mission!Rikudo Sennin has completed a tough C-rank mission!
Default Re: Increase the Forum's Security

Quote:
Originally Posted by Nick Tasogare View Post
STOP IT I'M GONNA SUFFOCATE!
Ok it seems you're not taking it seriously which means there is nothing to worry 'bout..so im just posting the results of my previous research since its now useless.

Spoiler:
Target Information
Target http://naruto.viz.com:80/forum/
Server banner Apache/2.2.4 (Ubuntu) PHP/5.2.3-1ubuntu6.5
Operating system Unix
Web server Apache 2.x
Technologies PHP

SSL 2.0 deprecated protocol
Vulnerability description
The remote service encrypts traffic using an old deprecated protocol with known weaknesses.
Affected items
Server
The impact of this vulnerability
An attacker may be able to exploit these issues to conduct man-in-the-middle attacks or decrypt communications between the affected service and clients.

also.

Insecure crossdomain.xml
Vulnerability description
The browser security model normally prevents web content from one domain from accessing data from another domain. This is commonly known as the "same origin policy". URL policy files grant cross-domain permissions for reading data. They permit operations that are not permitted by default. The URL policy file is located, by default, in the root directory of the target server, with the name crossdomain.xml (for example, at http://www.example.com/crossdomain.xml).

When a domain is specified in crossdomain.xml file, the site declares that it is willing to allow the operators of any servers in that domain to obtain any document on the server where the policy file resides. The crossdomain.xml file deployed on this website opens the server to all domains (use of a single asterisk "*" as a pure wildcard is supported) like so:
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
This practice is suitable for public servers, but should not be used for sites located behind a firewall because it could permit access to protected areas. It should not be used for sites that require authentication in the form of passwords or cookies. Sites that use the common practice of authentication based on cookies to access private or user-specific data should be especially careful when using cross-domain policy files.
Affected items
Server
The impact of this vulnerability
Using an insecure cross-domain policy file could expose your site to various attacks.
__________________


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Feed me some negative reps
no reverse psychology please

Do.not.be.Afraid
Rikudo Sennin is offline  
Old 11-12-2010, 09:03 PM   #10
TheBlackChidori
Special Jonin Candidate
 
TheBlackChidori's Avatar
 
Join Date: Apr 2009
Location: Wherever the Winds of Fate take me.
Posts: 14,869
Rep Power: 0
TheBlackChidori is just chillin' in the village doing D-ranks at this point
Default Re: Increase the Forum's Security

Quote:
Well I do hope this is real.
100%. There is no way that an instance like what happened before, could ever happen again. The Trouble Hacker was a flaw in the system, and we repaired that flaw. It could have buried us...but it did not, for that we are stronger.

I am confident we are safe from such things.
TheBlackChidori is offline  
Old 11-12-2010, 09:06 PM   #11
Nick Tasogare
Special Jonin Candidate
 
Nick Tasogare's Avatar
 
Join Date: Apr 2009
Location: Getting at you where you live.
Posts: 27,570
Rep Power: 20
Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.Nick Tasogare is one of the most respected ninja in  the village.
Send a message via Skype™ to Nick Tasogare
Default Re: Increase the Forum's Security

Seriously Windking, it's cool. Your vulnerability scan or whatever is just a.... How can I put this? Like a Genjutsu Trap. In actuality, the server.... It's invulnerable, impenetrable, whatever other word might fit. It's just been set up so that it will read as weak, and trick any other hackers. Don't worry dude, we're safe here.
__________________
Was on to check PMs and read about the drama and got hit with the forums rules.

Can Herr SRhyse and Frau Muffintop please remove my staff "powers"? The Mod Rules are a joke and everybody knows it lol I don't follow that last rule well enough, and I don't want to endanger the Communist Rule of the People's Republic of NDF. Thanks.

/Heil

Oh wait, now there's drama so I just have to watch this all blow up.
Nick Tasogare is offline  
Old 11-12-2010, 09:07 PM   #12
Vex
Special Jonin Candidate
 
Vex's Avatar
 
Join Date: Sep 2009
Location: Sep 2009
Posts: 20,376
Rep Power: 34
Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.
Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.Vex is the subject of legends and tales that shall be passed on for generations to come.
Default Re: Increase the Forum's Security

I think this is worthy of consideration, my prince. What can I do to help?
__________________

i'm not a hoe.
Vex is offline  
Old 11-12-2010, 09:14 PM   #13
Rikudo Sennin
7-Up Disciple
 
Rikudo Sennin's Avatar
 
Join Date: Dec 2009
Location: Me Want Negative Reps
Posts: 3,678
Rep Power: 8
Rikudo Sennin has completed a tough C-rank mission!Rikudo Sennin has completed a tough C-rank mission!
Default Re: Increase the Forum's Security

Quote:
Originally Posted by Nick Tasogare View Post
Seriously Windking, it's cool. Your vulnerability scan or whatever is just a.... How can I put this? Like a Genjutsu Trap. In actuality, the server.... It's invulnerable, impenetrable, whatever other word might fit. It's just been set up so that it will read as weak, and trick any other hackers. Don't worry dude, we're safe here.
I cracked acutenix v6.0 and did some scannings,, anyway as TBC was saying..Nothing to worry because it seems you people are stronger than those hackers..

..and im not of them now..
__________________


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Feed me some negative reps
no reverse psychology please

Do.not.be.Afraid
Rikudo Sennin is offline  
Old 11-12-2010, 09:24 PM   #14
TheBlackChidori
Special Jonin Candidate
 
TheBlackChidori's Avatar
 
Join Date: Apr 2009
Location: Wherever the Winds of Fate take me.
Posts: 14,869
Rep Power: 0
TheBlackChidori is just chillin' in the village doing D-ranks at this point
Default Re: Increase the Forum's Security

Either way, Viz has a tech department to handle such matters.
TheBlackChidori is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 04:56 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.