1
neogabo
Re: Is xoops Firesheep vulnerable?
  • 2010/10/28 7:07

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


In fact, firesheep is not stealing your user and password credentials , but your browser cookies.


Cookies + Same Public IP = HACKED


let me explain a litle bit:

If u are using a Wifi router then u must know that not encripted wifi networks are all vulnerable, but not the encripted ones(not really).

Now the thing is that with WEP the user that has a decrypt key(those that are loged in the router, can access internet) can hear and decrypt any loged user data. They have your cookies.

With Wap and Wap2 this was modified. But in the last defcom conference someone(i dont know who) showed a bug that allowed any loged user to decrypt other loged users data. So they have your cookies too.

So... the things is that firesheep can steal your cookies and then use those cookies to make the site think that is the correct user. Remember that if the 2 users are using the same wifi router u have the same public ip address.


SO: HACKED xD

Bank accounts, facebook accounts, twitter accounts .. . . .. . . .. .

ANYTHING!

EDIT:
ANYTHING! (Without the correct SSL protection)



2
neogabo
Re: Oledrion's license
  • 2010/4/15 14:46

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


ok great! thnz!!



3
neogabo
Re: Oledrion's license
  • 2010/4/15 14:36

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


xD yes clear as mud.

one more thing, can someone strip the coments about oledrion in the templates? (not the original ones but the ones in /themes/modules/oledrion )


"upgradable with the current version" , im not sure about that. i will probably modify the db struture and a lot of code



4
neogabo
Re: Oledrion's license
  • 2010/4/15 14:07

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


but if i continue the module and the real author apears can he/she change the license?

i dont have a problem with that comments or credits, but if the author changes the license for something not free, well ...



5
neogabo
Re: Oledrion's license
  • 2010/4/15 13:54

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


yes, you are right.

Look this:

/**
* ****************************************************************************
* oledrion - MODULE FOR XOOPS
* Copyright (c) Hervé Thouzard of Instant Zero (http://www.instant-zero.com)
*
* You may not change or alter any portion of this comment or credits
* of supporting developers from this source code or any supporting source code
* which is considered copyrighted (c) material of the original comment or credit authors.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
*
* @copyright Hervé Thouzard of Instant Zero (http://www.instant-zero.com)
* @licensehttp://www.fsf.org/copyleft/gpl.html GNU public license
* @package oledrion
* @author Hervé Thouzard of Instant Zero (http://www.instant-zero.com)
*
* Version : $Id:
* ****************************************************************************
*/

im not sure if i can add things to oledrion.



6
neogabo
Oledrion's license
  • 2010/4/15 13:23

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


Hi i would like to know if its posible to take oledrion and develop it more.

I mean, there are things that are really good, but others that needs a lot o development.

Due to the unfortunelly fact that instant zero "is not with us anymore" i ask:
can i take oledrion to use it "as a base" for another module?



Added(with edit)
there are a lots of:
<!-- Created by Instant Zero (http://www.instant-zero.com) -->, everywhere. i want to develop a totally free module, without all that



7
neogabo
$this->handler->keyName table prefix joint
  • 2010/2/26 18:28

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


in the line 139 of joint.php (function getCountByLink() ) there is now table prefix for $this->handler->keyName.

this generates an ambiguos sql error

Xoops version 2.4.4



8
neogabo
Re: addStylesheet in the admin
  • 2009/12/18 20:21

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


Thnz a lot trabis!

Solved !



9
neogabo
Re: addStylesheet in the admin
  • 2009/12/18 20:07

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


i tried, i can't get it to work:


xoops_cp_header();

$xoTheme->addStylesheet(XOOPS_URL . '/modules/yourmodule/style.css');

xoops_cp_footer();

Error:
Fatal error: Call to a member function addStylesheet() on a non-object .........


Version.php:
/**
* DEFINE Versioning
*/
define('XOOPS_VERSION', 'XOOPS 2.4.0');



10
neogabo
Re: addStylesheet in the admin
  • 2009/12/18 18:44

  • neogabo

  • Just popping in

  • Posts: 22

  • Since: 2009/11/9


?




TopTop
(1) 2 »



Login

Who's Online

209 user(s) are online (130 user(s) are browsing Support Forums)


Members: 0


Guests: 209


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits