PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 
Site Navigation

Home:

 
Donate o Meter
Help Keep Our Servers Online AND Our Services Free!
Make donations with PayPal!
Donations
 
Please Link To Me!
 
Quality Web Hosting For All PHP Applications
Quality PHP Web Host!

Great Reviews!
Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?
Need help customizing or designing scripts?
Please contact us via the Contact Us option for further details and pricing.

Link to Me

RavenPHPScripts

RavenPHPScripts

There are more Link To Me icons here.
 
Site Info v2.2.2 ©
Your IP: 38.107.179.233

 Welcome, Anonymous
Nickname
Password
Security Code:
Security Code
Type Security Code:

· Register
· Lost Password
Server Date/Time
8 February 2012 02:23:33 EST (GMT -5)
 
Giving SQL Injection the Respect it Deserves 
SecurityEven though this article is written in response to SQL Injection attacks in/on ASP/IIS, it is just as relevant to PHP/MySQL.

Michael Howard writes: You may have read recently about a large number of Web servers that were compromised through a SQL injection attack. The malicious SQL payload is very well designed, somewhat database schema agnostic and generic so it could compromise as many database servers as possible. While the attack was a SQL injection attack that attacked and compromised back-end databases courtesy of vulnerable Web pages, from a user's perspective the real attack was compromised Web pages that serve up malware to attack user's through their browsers. In essence, there were two sets of victims: the Web site operators and the users who visited the affected Web sites. In this post, I want to focus on what the first set of users, the Web site operators, can do to protect themselves.

The fact that the malicious payload was so generic shows that the science of SQL injection has not taken a back seat to research in other vulnerability types, such as buffer overflows or cross-site scripting issues.

I think the first lesson from this attack is this:

If you have a Web server (doesn't matter what type), and it's hooked up to a database (doesn't matter what type) you need to go in and review your code that performs the database work.

So now that you've determined the database access code, now what? The SDL is very specific about what do here, there are three requirements - they are requirements not recommendations, which means you must do the following coding requirements and defenses

* Use SQL Parameterized Queries
* Use Stored Procedures
* Use SQL Execute-only Permission
Posted by Raven on Saturday, May 31, 2008 @ 00:22:07 EDT (1420 reads)
(Read More... | 6929 bytes more | Score: 0)
Top ten worst spam registrars notified by ICANN 
InternetTop 10 Illicit Domain Registrars
CHINA - Xinnet Bei Gong Da Software, BEIJINGNN, Todaynic
GERMANY - Joker
USA - eNom, Inc., MONIKER, Dynamic Dolphin, The Nameit Co/AITDOMAINS.COM, PDR, Intercosmos/DIRECTNIC

In a response to the recently released cluster analysis of the top 10 worst domain registrars in terms of spam and junk content hosting domains, the ICANN has taken steps to approach the non-compliant registrars :

More than half of those registrars named had already been contacted by ICANN prior to publication of KnujOn’s report, and the remainder have since been notified following an analysis of other sources of data, including ICANN’s internal database. With tens of millions of domain names in existence, and tens of thousands changing hands each day, ICANN relies upon the wider Internet community to report and review what it believes to be inaccurate registration data for individual domains. To this end, a dedicated online system called the Whois Data Problem Report System (“WDPRS”) was developed in 2002 to receive and track such complaints. ICANN sends, on average, over 75 enforcement notices per month following complaints from the community. We also conduct compliance audits to determine whether accredited registrars and registries are adhering to their contractual obligations,” explained Stacy Burnette, Director of Compliance at ICANN. “Infringing domain names are locked and websites removed every week through this system.”

Read Full Story
Posted by Raven on Tuesday, May 27, 2008 @ 13:32:47 EDT (1362 reads)
( | Score: 0)
Age of Conan RavenNuke[tm] theme released 
RavenNukeMars writes "PortalThemes - Age of Conan RavenNuke(tm) Theme Released
Conan Red is a gorgeous fast loading RavenNuke(tm) Theme designed for an Age of Conan site.

Preview the Conan Red theme at the PortalThemes RavenNuke(tm) Themes test site.
(Select ConanRed in the top left dropdown list.)
Includes a matching forum theme.
PSD file included for the header.

Be sure to checkout our wide selection of RavenNuke(tm) Themes at our Theme Site
PortalThemes.com
"
Posted by Raven on Sunday, May 25, 2008 @ 08:26:26 EDT (1830 reads)
( | Score: 0)
NukeSentinel(tm) 2.5.18 Released 
NukeSentinel (tm)2.5.18 CHANGES (2008-05-23):
· Includes IP2Country 2008-05-19 updated imports.
· Not in upgrade package.
· XHTML compliance updates. (99% compliant)
· Updated graphics.
· Updated many of the admin scripts.
· Renamed many files to better fit naming scheme.
· Improved paging in admin pages.
· Updated DB Maintaince functions.
· Added DB Backup function.
· Replaced <marquee> tags with javascripting for XHTML compliance.
Posted by BobMarion on Friday, May 23, 2008 @ 22:18:23 EDT (1254 reads)
( | Score: 0)
pancake.org : sergids.com : MP3player and Top Music Module - see online-demos 
Add-Onsnukeevangelist writes "[click] Zina-module :: sergids.com

- Real Audio streaming
- Custom and Playlists
- RSS/Podcasts .. much more
"
Posted by Raven on Friday, May 23, 2008 @ 08:08:34 EDT (1125 reads)
( | Score: 0)
Nuke Guiki 1.3.0, an improved PHP-Nuke Wiki module 
Add-Onsnukeevangelist writes "A powerful module for phpnuke!

Hydronuke Project: Guiki is a Wiki module for PHPNuke. You can see it in action in the User Docs section of the site.

Features
* Auto-link generation
* Stores pages in database
* Graphical editing of site
* Basic search engine
* Delete pages in edit mode
* Simple code
* Easy to install
* Modification time records
* Extensive docs as part of the wiki.
* Build-in editor
* Easy to install
* Simple to use.
* Index page function
"
Posted by Raven on Friday, May 23, 2008 @ 08:05:33 EDT (2309 reads)
( | Score: 0)
FTC New E-mail Address for Deceptive Spam 
USA Newsnb1 writes "The Federal Trade Commission receives about 300,000 samples of deceptive spam – forwarded by computer users each day, and stores it in a database. The FTC and its law enforcement partners use the database to generate cases against people who use spam to spread false or misleading information about their products or services. To better handle the high volume of spam forwarded to the database, the FTC recently opened a new email box

The FTC’s spam database has served as the basis for FTC cases involving pyramid schemes, money-making chain letters, credit card scams, credit repair scams, bogus weight-loss plans, fraudulent business opportunities, and other scams that were promoted via email.

Consumers who wish to forward unwanted or deceptive spam to the FTC should use the New E-mail address. Whenever you complain about spam, it's important to include the full email header.

New E-mail Address
"
Posted by Raven on Thursday, May 22, 2008 @ 23:22:28 EDT (1213 reads)
( | Score: 0)
FileZilla GnuTLS Multiple Vulnerabilities 
Security SECUNIA ADVISORY ID: SA30330

VERIFY ADVISORY: http://secunia.com/advisories/30330/

CRITICAL: Highly critical

IMPACT: DoS, System access

SOFTWARE:
FileZilla 2.x http://secunia.com/product/2925/
FileZilla 3.x http://secunia.com/product/15691/

DESCRIPTION: Some vulnerabilities have been reported in FileZilla, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system. The vulnerabilities are caused due to the precompiled packages including a vulnerable version of the GnuTLS library. The vulnerabilities are reported in versions prior to 3.0.10.
Posted by Raven on Wednesday, May 21, 2008 @ 15:45:33 EDT (1216 reads)
(Read More... | 1272 bytes more | Score: 0)
ewebsite.biz: great hacks for articles, modules, blocks etc.  
Add-Onsnukeevangelist writes "Hello dear friends on Ravenphpscripts.com.

eWebsite.biz - php web design for designers do a good job. They have several great modules like e-weather, Index-mod, gMap-mod, and many more! Join the great developer site!

Also see MontegoScripts.com with his great html-newsletter
"
Posted by Raven on Tuesday, May 20, 2008 @ 07:30:06 EDT (905 reads)
( | Score: 0)
Wars Module 2.21 
Add-Onsnukeevangelist writes "Hello Friends at Ravenphpscritps!

See mods at udesigns.be
-Clan Members
-Statistics
"
Posted by Raven on Tuesday, May 20, 2008 @ 07:20:31 EDT (1016 reads)
( | Score: 0)
Partners

NuSphere PhpED
IDE for PHP, HTML, CSS, XML, SMARTY, XHTML
Special 10% off coupon! ALL-ACT-10-O-945A4
PHPRunner - PHP form builder
CSE HTML Validator
ip address masquerading
CoffeeCup Software
phpDesigner
PHP Editor/IDE for all PHP/Web development
Just Great Software
Clan-Themes
Making clans look good!
Code Authors
Home of Spam Blocker
Montego Scripts
HTML Newsletter Support

 
Recommended Sites
Montego Scripts - Home of HTML Newsletter

Code-Authors.com

nukeSEO.com

Totally Nuked Mods

EZ Communities - Custom PHP/MySQL Scripts and Solutions

RavenNuke(tm) Test site

Codezwiz Your #1 Help Resource

CSE HTML Validator Helped Clean up This Page!

PC Sympathy - Your Source for PC News and Technical Support

Mantis Bugtracker

Nuke-Evolution

TrickedOutNews.com - Home of Tricked Out News Mod, FaceBox and SlimBox RavenNuke(tm) mods

 
Old Articles

Wednesday, December 07
· Download.Com Caught Adding Malware to Nmap & Other Software (0)
· Spammers and Medications (0)
Sunday, December 04
· SQL Injection Attack happening ATM, 4000+ sites infected (0)
Monday, November 21
· PHP Programming (0)
· 28 Coolest Firefox About:Config Tricks (0)
· 10+ Best Firefox Security and Privacy Addons (0)
· How to Launch Firefox Instantly? (0)
Thursday, November 10
· Make Use Of (0)
· Outsmarted: Captcha security not much of a gotcha (0)
· Firefox Tweak Guide (0)
Saturday, October 22
· HTTPS Everywhere (0)
Sunday, October 16
· Race conditions in security dialogs (0)
· Firefox Keyboard and Mouse Shortcuts (0)
Sunday, October 02
· A Professional Slide Show PHPNuke block (0)
· Migrating from PHP 5.2.x to PHP 5.3.x (0)
· PHP encryption for the common man (0)
· Backup Your MySQL Database Using PHP (0)
· Graphical Support For Raven Nuke (0)
Tuesday, September 06
· Download The Brand New Rox and the Revamped Chely Themes for RavenNuke(tm) (0)
Monday, August 29
· PHP-Nuke Flash Player v0.3.2 (0)

Older Articles
 
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum