Talk Arcades: Forum for Arcade Webmasters    

  Talk Arcades > Arcades > Scripts & Software > phpArcadeScript

Welcome to Talk Arcades, the premier forum for arcade webmasters.

You are currently viewing our boards as a guest. By joining our community you will be able to make posts, communicate privately with other arcade webmasters and participate in our Live Marketplace. Registration is easy, so please join us today!

Reply
 
LinkBack Thread Tools Display Modes
Old 08-20-2008, 09:23 AM   #1 (permalink)
sly5
Preferred Member
 
sly5's Avatar
 
Join Date: Jul 2008
Location: On a platform somewhere in a station near you.
Posts: 168
sly5 is on a distinguished road


Default PHPAS V 4.0 security = big fail?

Big Dog Arcade was hacked recently and the webmaster has posted a message that says the following:

"We had designed some templates based on this Version 4.0, after having been told by the owners of PHP Arcade Script that it was ready to be released. However, this script was vulnerable to attack and now we decided to start this entire domain over from scratch."

Does anyone know what the security status on V4.0 is? Has anyone else experience problems?

Just glad I didn't decide to upgrade...
__________________
Check out The Sly5 Arcade Blog, it's hot!

Check out The Sly5 Games Arcade, it's hotter!
sly5 is offline  
Digg this Post!
Reply With Quote
Old 08-20-2008, 09:27 AM   #2 (permalink)
peter_anderson
Banned
Senior Member
 
Join Date: Jan 2008
Location: Who wants to know?
Posts: 1,593
peter_anderson is an unknown quantity at this point
Send a message via MSN to peter_anderson


Default

The message is on http://www.bigdogwebsitedesign.com/ not http://www.bigdogarcade.com/

v4 was going to have security problems - I knew from the start. People should never use BETA's until they are fully released.
peter_anderson is offline  
Digg this Post!
Reply With Quote
Old 08-20-2008, 09:46 AM   #3 (permalink)
sly5
Preferred Member
 
sly5's Avatar
 
Join Date: Jul 2008
Location: On a platform somewhere in a station near you.
Posts: 168
sly5 is on a distinguished road


Default

Quote:
Originally Posted by peter_anderson View Post
Sharp as a razor blade. Error corrected.
__________________
Check out The Sly5 Arcade Blog, it's hot!

Check out The Sly5 Games Arcade, it's hotter!
sly5 is offline  
Digg this Post!
Reply With Quote
Old 08-20-2008, 11:23 AM   #4 (permalink)
piczogame
Arcade Freestyler
Senior Member
 
piczogame's Avatar
 
Join Date: Sep 2007
Location: Scotland
Posts: 1,417
piczogame is on a distinguished road
Send a message via MSN to piczogame


Default

V4 isn't well designed out nor as it been given the right work to be even close to as finshed. I love phpas seriously but V4 looks to me is V3 with addons and alot of new open holes...

Wait till it offically comes out of BETA as from what i know its a sql injection exploit which maybe the cause as it has a past for it.

I woulded go near V4 at all as its a long way away from being stable and secure...
piczogame is online now  
Digg this Post!
Reply With Quote
Old 08-20-2008, 10:06 PM   #5 (permalink)
GetGamesHere
Preferred Member
 
Join Date: Jul 2008
Location: Arizona
Posts: 178
GetGamesHere is on a distinguished road


Default

A friend's site was hacked on v4. His logs showed the command to cause it, and it actually works on v3 also, so don't feel too safe with not upgrading. If you want to know how to protect against it, PM me, because I am not going to post the hack for potentially dangerous people to see. It's a disturbingly easy hack, so I wouldn't be surprised if other scripts could be exploited with a similar approach.
GetGamesHere is offline  
Digg this Post!
Reply With Quote
Old 08-20-2008, 10:39 PM   #6 (permalink)
piczogame
Arcade Freestyler
Senior Member
 
piczogame's Avatar
 
Join Date: Sep 2007
Location: Scotland
Posts: 1,417
piczogame is on a distinguished road
Send a message via MSN to piczogame


Default

The fix for V3 has been posted on the forum if you signin to the forum you will see it as "Extra Security For You V3" under the phpas owners only subforum.
piczogame is online now  
Digg this Post!
Reply With Quote
Old 08-21-2008, 12:01 AM   #7 (permalink)
GetGamesHere
Preferred Member
 
Join Date: Jul 2008
Location: Arizona
Posts: 178
GetGamesHere is on a distinguished road


Default

Thanks piczogamer, I didn't know that. I posted some additional suggestions there because the fix doesn't really address the issue, just makes it a little harder. But the full extent of the problem can be different for each of us depending on how much we modified it. I think the script is pretty good, just some portions of the security logic weren't fully implemented.
GetGamesHere is offline  
Digg this Post!
Reply With Quote
Old 08-21-2008, 12:30 AM   #8 (permalink)
piczogame
Arcade Freestyler
Senior Member
 
piczogame's Avatar
 
Join Date: Sep 2007
Location: Scotland
Posts: 1,417
piczogame is on a distinguished road
Send a message via MSN to piczogame


Default

Quote:
Originally Posted by GetGamesHere View Post
Thanks piczogamer, I didn't know that. I posted some additional suggestions there because the fix doesn't really address the issue, just makes it a little harder. But the full extent of the problem can be different for each of us depending on how much we modified it. I think the script is pretty good, just some portions of the security logic weren't fully implemented.
Its PiczoGame but friends call me antz,
I know phpas has issues and till this day still remains as the strongest most customisable script ever created so far. You coulded get more open coding than this thats sellable 100 times over... Nearly every arcade script has a failure somehow and they can't say that its 100% Perfect as nothing ever is. Heck were just human so cut them some slack lol.

I bet the other scripts are way worser just not been exploited yet because phpas is really populer with most top big arcades.
piczogame is online now  
Digg this Post!
Reply With Quote
Old 08-21-2008, 04:00 AM   #9 (permalink)
archgames
Senior Member
 
archgames's Avatar
 
Join Date: Jan 2008
Posts: 908
archgames is on a distinguished road
Send a message via MSN to archgames


Default

Quote:
Originally Posted by piczogame View Post
Nearly every arcade script has a failure somehow and they can't say that its 100% Perfect as nothing ever is.
Yep! You got it right... and i bet even if someone finds a fix to the problems another stupid hacker is going to try and find a new way to hack...it is a ongoing proccess and a ongoing war between the webmaster and hackers....Hopefully one day webmasters will win!

Thanks
Aash
__________________
Best Ad Networks : ValueClickMedia | Adsense
Arcades : Free Flash Games
Best arcade Host : HostGator | Hostmonster 4.95$ a mo great stuff!
Webmaster? : Trade 1:1 Traffic
Best Arcade Script : PHParcadeScript (includes 2.7k Games)

/\/\ My Recommendations....







archgames is online now  
Digg this Post!
Reply With Quote
Old 08-30-2008, 12:58 PM   #10 (permalink)
LearnNewbie
Preferred Member
 
Join Date: Jun 2007
Posts: 151
LearnNewbie is on a distinguished road


Default out of Beta?

Does anyone using phpas? look like they are out of beta but kinda look scary after the site got hack? lol


Anyway does anyone know phpas out of beta yet?
LearnNewbie is online now  
Digg this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Phpas Forum Integration Mod ArcadeSiteBuilder The Bazaar 4 07-19-2008 11:06 PM
New Template Fully Coded into phpAS in valid XHTML/CSS woochoochinchilla Themes and Graphics 2 10-03-2007 08:09 AM


All times are GMT -6. The time now is 12:03 AM.


Powered by vBulletin® Version 3.6.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0 RC6
© TalkArcades.com
Forum - Register - Calendar - Memberlist - FAQ - Search