
![]() |
![]() |
![]() |
|
|||||||
![]() |
![]() |
|
Welcome to Talk Arcades, the premier forum for arcade webmasters. You are currently viewing our boards as a guest. By joining our community you will be able to make posts, communicate privately with other arcade webmasters and participate in our Live Marketplace. Registration is easy, so please join us today! |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Preferred Member
Join Date: Jul 2008
Location: On a platform somewhere in a station near you.
Posts: 168
|
Big Dog Arcade was hacked recently and the webmaster has posted a message that says the following:
"We had designed some templates based on this Version 4.0, after having been told by the owners of PHP Arcade Script that it was ready to be released. However, this script was vulnerable to attack and now we decided to start this entire domain over from scratch." Does anyone know what the security status on V4.0 is? Has anyone else experience problems? Just glad I didn't decide to upgrade...
__________________
Check out The Sly5 Arcade Blog, it's hot! Check out The Sly5 Games Arcade, it's hotter! |
|
|
|
![]() |
![]() |
|
|
#2 (permalink) |
|
Banned
Senior Member
|
The message is on http://www.bigdogwebsitedesign.com/ not http://www.bigdogarcade.com/
v4 was going to have security problems - I knew from the start. People should never use BETA's until they are fully released. |
|
|
|
![]() |
![]() |
|
|
#3 (permalink) | |
|
Preferred Member
Join Date: Jul 2008
Location: On a platform somewhere in a station near you.
Posts: 168
|
Quote:
__________________
Check out The Sly5 Arcade Blog, it's hot! Check out The Sly5 Games Arcade, it's hotter! |
|
|
|
|
![]() |
![]() |
|
|
#4 (permalink) |
|
Arcade Freestyler
Senior Member
|
V4 isn't well designed out nor as it been given the right work to be even close to as finshed. I love phpas seriously but V4 looks to me is V3 with addons and alot of new open holes...
Wait till it offically comes out of BETA as from what i know its a sql injection exploit which maybe the cause as it has a past for it. I woulded go near V4 at all as its a long way away from being stable and secure...
__________________
ArcadeExchange.com - Independant Arcade Banner Exchange Service ----------------------------------------------------- Project Portal: Flashvolt.com 3 Month Project.
|
|
|
|
![]() |
![]() |
|
|
#5 (permalink) |
|
Preferred Member
Join Date: Jul 2008
Location: Arizona
Posts: 178
|
A friend's site was hacked on v4. His logs showed the command to cause it, and it actually works on v3 also, so don't feel too safe with not upgrading. If you want to know how to protect against it, PM me, because I am not going to post the hack for potentially dangerous people to see. It's a disturbingly easy hack, so I wouldn't be surprised if other scripts could be exploited with a similar approach.
|
|
|
|
![]() |
![]() |
|
|
#6 (permalink) |
|
Arcade Freestyler
Senior Member
|
The fix for V3 has been posted on the forum if you signin to the forum you will see it as "Extra Security For You V3" under the phpas owners only subforum.
__________________
ArcadeExchange.com - Independant Arcade Banner Exchange Service ----------------------------------------------------- Project Portal: Flashvolt.com 3 Month Project.
|
|
|
|
![]() |
![]() |
|
|
#7 (permalink) |
|
Preferred Member
Join Date: Jul 2008
Location: Arizona
Posts: 178
|
Thanks piczogamer, I didn't know that. I posted some additional suggestions there because the fix doesn't really address the issue, just makes it a little harder. But the full extent of the problem can be different for each of us depending on how much we modified it. I think the script is pretty good, just some portions of the security logic weren't fully implemented.
|
|
|
|
![]() |
![]() |
|
|
#8 (permalink) | |
|
Arcade Freestyler
Senior Member
|
Quote:
I know phpas has issues and till this day still remains as the strongest most customisable script ever created so far. You coulded get more open coding than this thats sellable 100 times over... Nearly every arcade script has a failure somehow and they can't say that its 100% Perfect as nothing ever is. Heck were just human so cut them some slack lol. I bet the other scripts are way worser just not been exploited yet because phpas is really populer with most top big arcades.
__________________
ArcadeExchange.com - Independant Arcade Banner Exchange Service ----------------------------------------------------- Project Portal: Flashvolt.com 3 Month Project.
|
|
|
|
|
![]() |
![]() |
|
|
#9 (permalink) | |
|
Senior Member
|
Quote:
![]() Thanks Aash
__________________
Best Ad Networks : ValueClickMedia | Adsense
Arcades : Free Flash Games Best arcade Host : HostGator | Hostmonster 4.95$ a mo great stuff! Webmaster? : Trade 1:1 Traffic Best Arcade Script : PHParcadeScript (includes 2.7k Games) /\/\ My Recommendations.... |
|
|
|
|
![]() |
![]() |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Phpas Forum Integration Mod | ArcadeSiteBuilder | The Bazaar | 4 | 07-19-2008 11:06 PM |
| New Template Fully Coded into phpAS in valid XHTML/CSS | woochoochinchilla | Themes and Graphics | 2 | 10-03-2007 08:09 AM |