Jump to content

Yoh Asakura

Members
  • Content Count

    261
  • Joined

  • Last visited

  • Days Won

    2

Posts posted by Yoh Asakura


  1. Which forum do you guys prefer?

     

    I've made a research and I believe most of people prefer the MyBB since it's free and seems better than the others, but I saw many users talking about SQL Injection on their MyBB forum and the reason is because of the addons that they add, some of them still have some bugs and might be exploitable.  What do you guys think and know about?

     

    IPB Board is also really good but it's a paid forum.


  2. @@Arei

    I appreciate the support you gave me.

     

    I didin't use any FluxCP custom themes nor even custom addons.

    I believe they did the SQL Injection because of my website...the coder just told me that the php of my website was very old and he will update all now and make it better.


  3. @@Arei

    Follow some screenshots of my server email.

     

    These things also appeared on my login table from my server database.

     

    It was definetly SQL Injection through my website contact page and also through my website donation confirmation page.

     

    post-3532-0-84029100-1434479600_thumb.jpg

     

    post-3532-0-59523700-1434479602_thumb.jpg

     

    post-3532-0-65059900-1434479603_thumb.jpg


  4. @@Arei

    I just called SiteLock and they've told me that I might have a Firewall, and they can provide me a good one, that helps to protect against SQL Injections, and they also have the deep scan...malwares, virus, malicious codes. SQL Injection Scan, etc. But it's like between $50~$140/month.


  5. @@Arei

    Thanks for helping.

    I will change company, I'm going to buy a VPS on Godaddy. At least there I can have their managed service, with security, monitoring and backups. And the VPS already comes with MYSQL (I was using BudgetVM without managed service, so I've made all the installations).

    And what do you mean that is possible to make a SQL Injection through my RO Scripts? o.o

     

    @@evilpuncker

    I was using Ceres CP when they first hacked the servers, but then I've changed to fluxcp and they still hacked, but I think it's not related with the Panels....I believe it's about the MYSQL. I may have not installed and secured it very well, and also can be my website. Maybe the guy who developed it didin't made the scripts so well...who knows.


  6. @@Arei

    I wasn't using FluxCP when the servers were hacked. My website has a registration script to register new accounts, but I don't know how the hackers got access to all the servers accounts.

    I've also checked the IP's that logged on my VPS, and only my IP's appeared, which means that the hackers didin't get the acces of my VPS...

    Do you think is better having a Web Hosting for my site and a VPS for the server or better website and server on the VPS?


  7. I believe the hackers did SQL Injection...I've saw many strange columns on my login table and also on my server email adress.

     

    I remember I had removed the remote login acess from MYSQL...and the passwords were very strong...


  8. Hello,

     

    I have three servers and recently all of them has been hacked somehow. I don't know how because I already let phpmyadmin acces only to my IP Adress and I also changed the phpmyadmin folder.

     

    Is there anyway I can protect my server? I believe it's about the MYSQL, php and phpmyadmin installation.

     

    Anyone could help me on this?

     

    Regards.


  9. @@Emistry

    I've just tested here and if I buy more than 1 item I will only receive the 1st item that I put to purchase and on SQL will only appear the 1st item too...


  10. @@evilpuncker

     

    I believe you didin't get me.

     

    I would like a script for vote4points just like the quest_shop.txt script.
    A script that when you click it will open the shop window with the items to choose, not only the name of the items, but also their images.... after you choose and click on buy it will tell you how much POINTS OF VOTE it costs.

    It would also be nice to choose the quantity, and choosing the quantity it would change the amount of vote4points needed.

     

    Is it possible?


  11. @@evilpuncker

     

    I've just tested the version 1.0 and it worked, I just wonder if it's possible to change the script...I would like the script like the quest_shop (npc/custom/quests/quest_shop.txt), that shows the item image, and to buy the item you'd need the votepoints, and if possible to set how many of that item you'd like.

     

    voteforpoints.txt


  12. @@evilpuncker

    It worked.

     

    By the way, I can see here that it shows all the chars of the GM's accounts, but I have an old script that only show that "GM Yoh Asakura" was online, instead of showing all the chars of my account. It gets the account ID instead of the groupID.

     

    Is it possible to make this change for me?


  13. @@evilpuncker

    I already changed Timezone at application.php and servers.php. I put all like "America/New_York" and I also tried to put number, like -3:00 but I get error saying I can't use : or -

     

    Warning: date(): It is not safe to rely on the system's timezonesettings. You are *required* to use the date.timezone setting or thedate_default_timezone_set() function. In case you used any of thosemethods and you are still getting this warning, you most likelymisspelled the timezone identifier. We selected the timezone 'UTC' fornow, but please set date.timezone to select your timezone. in /var/www/html/lib/Flux/Connection/Statement.php on line 14
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.