Cobra Club Forums
Cobra Club Forums

Welcome to the Cobra Club Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   Cobra Club Forums > General Discussion > General Cobra Discussion
Home Forums Blogs Videos Gallery Cobra Marques Info Groups Classifieds Gallery Arcade Shopping
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-04-03, 11:30 AM
robert's Avatar
Administrator
 
Join Date: Jan 1999
Location: Northampton, Northampton, UK.
Age: 38
Posts: 8,574
Fiero Factory Security

I sent the Webmaster of the site a mail over a week ago with no response, so I am posting the info here for members information.

The Fiero Factory website is insecure. The user database is wide open, as is the setup file.

This is what I was able to pull off the site, a subset of the user database and a portion of the setup file.

xxxxx|Andy Green|admin|Andrew|Green|xxxxx@raima.co.uk|on
xxxxx|Steve|normal|Stephen|Briddon|xxxxx@fierofact ory.org|on
xxxxx|Andy|admin|Andrew|Green|xxxxx@agwebsites.co. uk|on
xxxxx|jawsbyte|normal|John|Williams|john.williams@ xxxxx.net|on
xxxxx|mike|normal|mike|shepherd|steeringeng@xxxxx. com|on
xxxxx|rocket|normal|Roger|Williamson|r.williamson1 @xxxxx.com|on
xxxxx|Andrew|normal|Andrew|Green|xxxxx@agsite.co.u k|on

# $cgiurl is the URL corresponding to $cgidir
# Use full URL

$cgiurl = "http://www.fierofactory.org/cgi-bin/dcforum";

# $maindir is the directory path to the /htdocs/dcforum

$maindir = "/xxxxx/xxxxx/_f/_i/_e/fierofactory.org/public/www/dcforum";

# $mainurl is the URL corresponding to $maindir

$mainurl = "http://www.fierofactory.org/dcforum";


The information to correctly configure the security is part of the install documents.
__________________
Best Regards

Robert

My Son had a toy steering wheel which he used to spin furiously, making loads of go-faster noises, leaning into all the tight corners, perhaps running the government feels a bit like that. You make all the noises, but when you stop you haven't really gone anywhere.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2 (permalink)  
Old 11-04-03, 12:18 PM
Miket's Avatar
Fully Paid Up Grandad
 
Join Date: Jul 2001
Location: Newton Abbot, Devon, UK. (God's waiting room)
Age: 60
Posts: 10,182
RE: Fiero Factory Security

>
>The Fiero Factory website is insecure. The user database is
>wide open, as is the setup file.
>

That doesn't surprise me one bit.
__________________
AK 427 FOR SALE


PistonHeads AK for sale


Mike
AK Sportscars
355 Hauser Chevy

The old believe everything, the middle-aged suspect everything, the young know everything.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3 (permalink)  
Old 11-04-03, 02:03 PM
Senior Member
 
Join Date: Jan 2002
Location: Warwickshire, England.
Posts: 245
RE: Fiero Factory Security

Are we (by default) "registered" with this site then?

Can we all go in and delete our userids :+ or other peoples (but who would do something like that?) {-} {-}
__________________
Welcome back my friends to the build that never ends....
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4 (permalink)  
Old 11-04-03, 02:12 PM
robert's Avatar
Administrator
 
Join Date: Jan 1999
Location: Northampton, Northampton, UK.
Age: 38
Posts: 8,574
RE: Fiero Factory Security

>Are we (by default) "registered" with this site then?

No, we are not registered by default on the fiero factory site.

>Can we all go in and delete our userids :+ or other peoples
>(but who would do something like that?) {-} {-}

No, it would be illegal to run Lophtcrack on the user database and enumerate the passwords, hence the reason I have deleted the passwords from the post above.
__________________
Best Regards

Robert

My Son had a toy steering wheel which he used to spin furiously, making loads of go-faster noises, leaning into all the tight corners, perhaps running the government feels a bit like that. You make all the noises, but when you stop you haven't really gone anywhere.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5 (permalink)  
Old 11-04-03, 02:48 PM
Senior Member
 
Join Date: Jul 2003
Location: Brighton or Nr Derby, UK.
Posts: 503
RE: Fiero Factory Security

Thanks Robert,

You know my email address so why didn't you contact me directly about it.

When I have found problems with your forum in the past I have both emailed you the information and tried to help you fix them with as much information as posible.

Well I guess you have shown your true colours to everyone now!!

Andy



http://www.corporanda.com/cos-race.gif

http://www.fierofactory.org
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #6 (permalink)  
Old 11-04-03, 03:00 PM
ejr ejr is offline
Junior Member
 
Join Date: Jun 2002
Location: Aslockton, Nottingham, Notts, UK.
Posts: 20
RE: Fiero Factory Security


>>
>>The Fiero Factory website is insecure. The user database is
>>wide open, as is the setup file.
>>

>That doesn't surprise me one bit.

May I ask why ?


eric.rundle@ntu.ac.uk
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #7 (permalink)  
Old 11-04-03, 03:00 PM
robert's Avatar
Administrator
 
Join Date: Jan 1999
Location: Northampton, Northampton, UK.
Age: 38
Posts: 8,574
RE: Fiero Factory Security

Andy

Please re-read my original post.

"I sent the Webmaster of the site a mail over a week ago with no response, so I am posting the info here for members information."
__________________
Best Regards

Robert

My Son had a toy steering wheel which he used to spin furiously, making loads of go-faster noises, leaning into all the tight corners, perhaps running the government feels a bit like that. You make all the noises, but when you stop you haven't really gone anywhere.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #8 (permalink)  
Old 11-04-03, 03:03 PM
Senior Member
 
Join Date: Jul 2003
Location: Brighton or Nr Derby, UK.
Posts: 503
RE: Fiero Factory Security

I have been through my emails and I have not received one email from you regarding the matter. I have other emails from you set last week so that would suggest you never did send an email.


Andy

http://www.corporanda.com/cos-race.gif

http://www.fierofactory.org
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #9 (permalink)  
Old 11-04-03, 03:10 PM
robert's Avatar
Administrator
 
Join Date: Jan 1999
Location: Northampton, Northampton, UK.
Age: 38
Posts: 8,574
RE: Fiero Factory Security

Andy

The emails are in my sent box.

Regarding your recent emails to me.

1. I am not a t*at
2. I did not hack your site, the information is readily available to anyone who cares to look at it. I suggest you secure the server before accusing me of hacking the site and look forward to hearing from your legal team in due course.
__________________
Best Regards

Robert

My Son had a toy steering wheel which he used to spin furiously, making loads of go-faster noises, leaning into all the tight corners, perhaps running the government feels a bit like that. You make all the noises, but when you stop you haven't really gone anywhere.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #10 (permalink)  
Old 11-04-03, 03:30 PM
Senior Member
 
Join Date: Jul 2003
Location: Brighton or Nr Derby, UK.
Posts: 503
RE: Fiero Factory Security

If you emailed me through the forum then it wouldn't have been stored in your sent box now would it!

Andy



http://www.corporanda.com/cos-race.gif

http://www.fierofactory.org
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Fiero factory up for sale. simon General Cobra Discussion 6 13-02-07 08:47 PM
Fiero Screeb General Cobra Discussion 0 21-04-06 10:57 PM
Fiero Factory Woes Purple AK General Cobra Discussion 18 15-02-04 09:04 PM
Do not buy a Kit from Fiero Big Bloke General Cobra Discussion 81 12-11-03 10:12 AM
Fiero Factory Euro 427 agwebsites General Cobra Discussion 3 07-11-02 09:37 PM


All times are GMT. The time now is 11:36 PM.


Powered by vBulletin® Version 3.7.0 Beta 4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0