Bitcoin Forum
April 26, 2024, 01:45:53 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 »  All
  Print  
Author Topic: cryptsy  (Read 32249 times)
r3wt
Hero Member
*****
Offline Offline

Activity: 686
Merit: 504


always the student, never the master.


View Profile
April 18, 2015, 03:33:12 AM
 #21

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.

My negative trust rating is reflective of a personal vendetta by someone on default trust.
If you see garbage posts (off-topic, trolling, spam, no point, etc.), use the "report to moderator" links. All reports are investigated, though you will rarely be contacted about your reports.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
sgk
Legendary
*
Offline Offline

Activity: 1470
Merit: 1002


!! HODL !!


View Profile
April 18, 2015, 08:10:18 AM
 #22

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.

But it is open-source now, so these vulnerabilities will be easy to find and fix.
okae
Legendary
*
Offline Offline

Activity: 1401
Merit: 1008


northern exposure


View Profile WWW
April 18, 2015, 04:01:02 PM
 #23

ty @crypto-maniac for this open source code, i really apreciate it, TY!!

IMHO #1.b of suspects, Hal Finney is/was S.N.
bitvestor
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


View Profile
April 19, 2015, 08:51:22 AM
 #24

This is great and its opensource, really appreciated and i feel bad that your original dream for this was kicked away because of laws and trust when you decide to sell and make profit for your time and effort..

For those asking about security and so on, its opensource now so get yourself to work if you actually need it..
r3wt
Hero Member
*****
Offline Offline

Activity: 686
Merit: 504


always the student, never the master.


View Profile
April 19, 2015, 02:23:25 PM
 #25

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.

But it is open-source now, so these vulnerabilities will be easy to find and fix.

Yeah, but it still won't scale and its still succeptible to other vulnerabilities.

My negative trust rating is reflective of a personal vendetta by someone on default trust.
Crypto-Maniac (OP)
Newbie
*
Offline Offline

Activity: 57
Merit: 0


View Profile WWW
April 20, 2015, 11:38:43 AM
 #26

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.

thx you R3wt for these words ....

its definly more easy to run  scanner from Kali ,instead code from scratch this open source exchange Smiley

you cannot sweep the work just for some basic (important also) security breach

also as i said exploit need POC so please if you can report and show it would be a good contribution at least

you wont find LFi/RFi here , maybe an xss or sql injection as u find

as other members remind it is open source and i didnt recommend to anyone here or via PM to run the site straigh like this

it flow from sense that if you like to run an exchange you must pay a DEV and security guy (a real one..)

i would recommend to also change request $GET  to $POST




mistercoin
Legendary
*
Offline Offline

Activity: 1042
Merit: 1000


https://r.honeygain.me/XEDDM2B07C


View Profile WWW
April 20, 2015, 01:10:59 PM
 #27

Amazing. I still have to crawl through the code to see if it truly is malware-free and not an attempt to harm, but if you honestly did release this Open source and clean to us, a lot of people could take a lesson from you as this is no small feat.

Thank you. Smiley

mistercoin
Legendary
*
Offline Offline

Activity: 1042
Merit: 1000


https://r.honeygain.me/XEDDM2B07C


View Profile WWW
April 20, 2015, 01:12:03 PM
 #28

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.

thx you R3wt for these words ....

its definly more easy to run  scanner from Kali ,instead code from scratch this open source exchange Smiley

you cannot sweep the work just for some basic (important also) security breach

also as i said exploit need POC so please if you can report and show it would be a good contribution at least

you wont find LFi/RFi here , maybe an xss or sql injection as u find

as other members remind it is open source and i didnt recommend to anyone here or via PM to run the site straigh like this

it flow from sense that if you like to run an exchange you must pay a DEV and security guy (a real one..)

i would recommend to also change request $GET  to $POST






I will clean up some of the security holes and submit pull requests if you would like me to?

r3wt
Hero Member
*****
Offline Offline

Activity: 686
Merit: 504


always the student, never the master.


View Profile
April 20, 2015, 03:09:48 PM
 #29

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.

thx you R3wt for these words ....

its definly more easy to run  scanner from Kali ,instead code from scratch this open source exchange Smiley

you cannot sweep the work just for some basic (important also) security breach

also as i said exploit need POC so please if you can report and show it would be a good contribution at least

you wont find LFi/RFi here , maybe an xss or sql injection as u find

as other members remind it is open source and i didnt recommend to anyone here or via PM to run the site straigh like this

it flow from sense that if you like to run an exchange you must pay a DEV and security guy (a real one..)

i would recommend to also change request $GET  to $POST


Looking through your source code, i found many of the same vulnerabilities that were in the original OpenEx scripts that i cowrote(In fact, some of the code is copied directly from OpenEx source code). To put it into perspective, i had no idea what i was doing back then(first experience with programming, delusional about my abilities). I do now:

https://github.com/OpenExLLC/web   -- No Release candidate yet
https://github.com/OpenExLLC/live    --0.1 Release
https://github.com/OpenExLLC/mail  -- Release Candidate is untested


This exchange will be scalable, secure, and just generally awesome. If anyone wants to join this effort, you're more than welcome to. There are other components to the system, however these are the only ones i've made public at this time, Mostly because some are yet to be implemented or are waiting on other things to be completed so they can be tested.

My negative trust rating is reflective of a personal vendetta by someone on default trust.
Crypto-Maniac (OP)
Newbie
*
Offline Offline

Activity: 57
Merit: 0


View Profile WWW
April 25, 2015, 12:27:22 PM
 #30

Thx you R3wt of course i will accept your your pull request Smiley



tyz
Legendary
*
Offline Offline

Activity: 3360
Merit: 1530



View Profile
May 01, 2015, 09:56:16 PM
 #31

Has someone already installed the script? Is it working the way the creator is promising?
diddledum
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
August 26, 2015, 10:29:00 AM
 #32

I would like to have this running on my site if there are no backdoors

I would appreciate some help from anyone to get this on a domain if all is ok Smiley
alwinlinzee
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
August 26, 2015, 12:31:45 PM
 #33

This is not an open source entirely because someone still need to pay 0.50btc to activate it to full version which include voting and chatting stuffs but is that price negotiable and do you offer free installations?

tyz
Legendary
*
Offline Offline

Activity: 3360
Merit: 1530



View Profile
August 26, 2015, 05:31:36 PM
 #34

Well, i would still like to know if someone installed and run the script in production?

Has someone already installed the script? Is it working the way the creator is promising?
Pab
Legendary
*
Offline Offline

Activity: 1862
Merit: 1012


View Profile
August 28, 2015, 01:50:24 AM
 #35

 Hi ,thank you
i will let know some honest people about your work,ifanybody will be intersted in to run exchange,i will let you know.You really deserve to get some money,maybe in some future will be possible to make a kind of decantrelised ,secure exchange on that base

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Pab
Legendary
*
Offline Offline

Activity: 1862
Merit: 1012


View Profile
August 28, 2015, 01:59:56 AM
 #36

Hi ,thank you
i will let know some honest people about your work,ifanybody will be intersted in to run exchange,i will let you know.You really deserve to get some money,maybe in some future will be possible to make a kind of decantrelised ,secure exchange on that base

Your link is showing not found,i sent you pm

https://github.com/crypto-maniac/Cryptsy-Clone

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
tyz
Legendary
*
Offline Offline

Activity: 3360
Merit: 1530



View Profile
August 28, 2015, 06:19:18 PM
 #37

I know it some time ago of you post but could you point to the files and lines where you find these vulnerabilities?

multiple SQL injection vulnerabilities.

this is not anywhere close to professional.
Yofun
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
August 28, 2015, 06:29:13 PM
 #38

Hey OP? link to source code is broken?
tyz
Legendary
*
Offline Offline

Activity: 3360
Merit: 1530



View Profile
August 28, 2015, 06:56:52 PM
 #39

Yeap, it seems he took it offline. Maybe too much security holes and flaws in the script.

Hey OP? link to source code is broken?
SparkedDev
Hero Member
*****
Offline Offline

Activity: 896
Merit: 1000


View Profile
August 29, 2015, 11:46:46 PM
 #40

If anyone has the files and are willing to work with us we would be happy to fix the code a push an updates with no holes.



.
.BITVEST DICE.
HAS BEEN RELEASED!


▄████████████████████▄
██████████████████████
██████████▀▀██████████
█████████░░░░█████████
██████████▄▄██████████
███████▀▀████▀▀███████
██████░░░░██░░░░██████
███████▄▄████▄▄███████
████▀▀████▀▀████▀▀████
███░░░░██░░░░██░░░░███
████▄▄████▄▄████▄▄████
██████████████████████

▀████████████████████▀
▄████████████████████▄
██████████████████████
█████▀▀█▀▀▀▀▀▀██▀▀████
█████░░░░░░░░░░░░░████
█████░░░░░░░░░░░░▄████
█████░░▄███▄░░░░██████
█████▄▄███▀░░░░▄██████
█████████░░░░░░███████
████████░░░░░░░███████
███████░░░░░░░░███████
███████▄▄▄▄▄▄▄▄███████

██████████████████████
▀████████████████████▀
▄████████████████████▄
███████████████▀▀▀▀▀▀▀
███████████▀▀▄▄█░░░░░█
█████████▀░░█████░░░░█
███████▀░░░░░████▀░░░▀
██████░░░░░░░░▀▄▄█████
█████░▄░░░░░▄██████▀▀█
████░████▄░███████░░░░
███░█████░█████████░░█
███░░░▀█░██████████░░█
███░░░░░░████▀▀██▀░░░░
███░░░░░░███░░░░░░░░░░

██░▄▄▄▄░████▄▄██▄░░░░
████████████▀▀▀▀▀▀▀██
█████████████░█▀▀▀█░███
██████████▀▀░█▀░░░▀█░▀▀
███████▀░▄▄█░█░░░░░█░█▄
████▀░▄▄████░▀█░░░█▀░██
███░▄████▀▀░▄░▀█░█▀░▄░▀
█▀░███▀▀▀░░███░▀█▀░███░
▀░███▀░░░░░████▄░▄████░
░███▀░░░░░░░█████████░░
░███░░░░░░░░░███████░░░
███▀░██░░░░░░▀░▄▄▄░▀░░░
███░██████▄▄░▄█████▄░▄▄

██░████████░███████░█
▄████████████████████▄
████████▀▀░░░▀▀███████
███▀▀░░░░░▄▄▄░░░░▀▀▀██
██░▀▀▄▄░░░▀▀▀░░░▄▄▀▀██
██░▄▄░░▀▀▄▄░▄▄▀▀░░░░██
██░▀▀░░░░░░█░░░░░██░██
██░░░▄▄░░░░█░██░░░░░██
██░░░▀▀░░░░█░░░░░░░░██
██░░░░░▄▄░░█░░░░░██░██
██▄░░░░▀▀░░█░██░░░░░██
█████▄▄░░░░█░░░░▄▄████
█████████▄▄█▄▄████████

▀████████████████████▀




Rainbot
Daily Quests
Faucet
Pages: « 1 [2] 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!