Home
Home

Directory
Directory

Articles
Internet Business Articles

Site Tools
SEO Tools
Server Tools
HTML Tools
DNS Inspector

Store Carts
Cart Reviews
Cart Demos

Venue Charts
Channel Traffic Rankings
OAI Stock Quotes and Charts
eBay's Worst Feedback

Forum
Forum Home
TulipTools News
Advertising
Blogging
Computer Hardware
Domain Names
Forum
Forum Home
TulipTools News
Advertising
Blogging
Computer Hardware
Domain Names
Ecommerce
Financing
Int'l Trading
Graphics and HTML
Internet Access
Legal Issues
Internet Business
Auction Sites
Classified Ad Sites
Fixed Price Venues
Operating Systems
Programming
Search Engines
Internet Security
Software
Web Hosting
Webmaster Issues
Reviews
Announcements
Off Topic Discussion

Web Hosting
TulipHosting

Domain Names
TulipDomains

Web Stats
TulipStats

Forum Rules
Forum Rules
Privacy Policy

Site Map
Forum Sitemap
Sitemap Topics


TulipTools Internet Business Owners and Online Sellers Community Forums

  • March 14, 2010, 09:55:27 AM *
  • Welcome, Guest
Please login or register.

Login with username, password and session length
French German Italian Dutch Spanish Portuguese Korean Chinese Simplified Japanese Greek Arabic Russian
Advanced search  

News:

Welcome to the TulipTools Internet Business Owners and Online Sellers Community Forums .  Now with 300 Discussion Boards to choose from...
:squirrel2: ...and almost as many smilies.

AlsoShop Auctions has averaged an abysmal $57 in daily sitewide sales since opening in 2008.  The top 10 SELLERS have PURCHASED over 70% of the items sold on the site since it opened .... the latest stats here

Bookmark and Share
Pages: 1 ... 26 27 [28] 29 30 ... 66   Go Down

Author Topic: PlunderHere and AlsoShop: A Web of Privacy Violations, Backstabbing, and Deceit  (Read 64053 times)

0 Members and 1 Guest are viewing this topic.

regic

  • Tulip Overlord
  • Lawnmower Mouth
  • *****
  • Karma: 281
  • Offline Offline
  • Gender: Female
  • Posts: 2745
  • Bite Me!

why did you [TheTradersPost] choose a script with a history of security problems?
http://www.google.com/search?q=secunia+and+softbiz+classifieds&btnG=Search&hl=en&c2coff=1&safe=off&rls=GGGL%2CGGGL%3A2006-26%2CGGGL%3Aen&sa=2

The scriptmaker hasn't fixed a security problem which the US Government's US-CERT rates as "High Risk"
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5122

The security alert was issued in September 2007.  Why didn't you check the script's history before you bought it?

Quote
Overview

SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter.

Impact

CVSS Severity (version 2.0):
CVSS v2 Base score: 7.5 (High) (AV:N/AC:L/Au:N/C:P/I:P/A:P) (legend)
Impact Subscore: 6.4
Exploitability Subscore: 10.0

Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: Provides unauthorized access, Allows partial confidentiality, integrity, and availability violation , Allows unauthorized disclosure of information , Allows disruption of service

Anybody with access to Google could find the instructions for hacking the script because it is on the first page of search results for "softbiz classifieds".  Didn't you notice that 4 of the 10 results on page one of a Google search for the script pertain to the script's security problems???
Quote
Softbiz Classifieds PLUS (id) Remote SQL Injection Vulnerability      Archive
Classifieds SQL INJECTION #### #### BY IRCRASH #### ##################################################################################### # # #AUTHOR ...
www.milw0rm.com/exploits/4457


If you haven't done so already, I'd immediately delete the affected store_info.php file from your server because anyone could use that exploit to take full control of your server and all of the sites and databases on it.  The exploit code has been available on the web for nearly 9 months and it is a really easy vulnerability to take advantage of  (hence the 10.0 exploitability subscore).
Logged

BellisimaJ.

  • Advertiser
  • Rabble-Rouser
  • *
  • Karma: 148
  • Offline Offline
  • Gender: Female
  • Posts: 6602

xwpopper: I must have missed your response. Sorry.

Some of what you say is technically correct, however, id theft can be accomplished with the info on that site, and in fact, with less info.

Yes, many people permit easy access to that info, but that is their choice.

If you don't realize that you are putting yourself at risk , because the risks of a certain site owner's negligence have not been explained to you, that is not your choice.

Therein lies the difference.
Logged

jezebel

  • Tulip Fanatic
  • *******
  • Karma: 69
  • Offline Offline
  • Gender: Female
  • Posts: 1380
  • Stupid people are a waste of oxygen.

TTP
SSL: minor security problem
SQL injection vulnerability: major security problem from day 1

Quote
Why didn't you check the script's history before you bought it?

rule #1: check SecurityFocus, Secunia, OSVDB, Packet Storm, Us-Cert, etc before buying or installing any script
rule #2: never install a script hat has an unpatched vulnerability
Logged

RiverRat

  • Rats are Exactly That ;)
  • Plum Devotee
  • ******
  • Karma: 327
  • Offline Offline
  • Gender: Female
  • Posts: 694
  • Stupidity is its own punishment.

TTP
SSL: minor security problem
SQL injection vulnerability: major security problem from day 1

Quote
Why didn't you check the script's history before you bought it?

rule #1: check SecurityFocus, Secunia, OSVDB, Packet Storm, Us-Cert, etc before buying or installing any script
rule #2: never install a script hat has an unpatched vulnerability

Lesson learned.  Problem removed and issue thereby resolved.
Logged

Never argue with an idiot they drag you down to their level then beat you with experience.

BellisimaJ.

  • Advertiser
  • Rabble-Rouser
  • *
  • Karma: 148
  • Offline Offline
  • Gender: Female
  • Posts: 6602

Quote
Stupidity is its own punishment.

 :angel1:

Logged

justabella

  • Tiny Tool
  • **
  • Karma: 1
  • Offline Offline
  • Posts: 10

  :toothy1:  PH...

The man behind the curtain is going to change scripts.......
Logged

regic

  • Tulip Overlord
  • Lawnmower Mouth
  • *****
  • Karma: 281
  • Offline Offline
  • Gender: Female
  • Posts: 2745
  • Bite Me!

uh oh :blinkie:
Logged

bargainbloodhound

  • Advertiser
  • Lawnmower Mouth
  • *
  • Karma: 318
  • Offline Offline
  • Posts: 4333
  • Member

Quote from: Plunderhere
What I can tell you so far is this:

1) We know we can transfer:

User Database
Auctions
Images
Store items
Feedback

We cannot transfer stores however once auctions transfered over
you just 'open store' and click on which items you want to appear
in store with probid. Store names 'may' be able to be brought over
and definitely all store items can be imported as auctions.

We cannot transfer items into categories so what we would do is
have one category for all PH items and then you the user must
allocate one or two categories for your items.

What would we do in what order?

1) Very latest version is being released any day which we would
acquire and then test the databases prior to any moves.

2) Once done and we are happy we would add the required modifications
whilst applying new design.

3) After satisfactory stage 2 of testing we would need 2 days to move
over and activate new script fully. (approximately)

The probid script is very fast and efficient and very search engine friendly.
Also easy to maintain on server and to back up.

We will upgrade a few things this week on current site and attempt to fix
the bugs as I see a few other Rscript sites are also having some severe
issues with the script.

I will do everything I can to maintain the same feel of the current site with
only the updating of design but you will still have forums as they are but I
will be adding:

1) Blogs
2) IM (Internal messenging)
3) Classified area
4) Video uploading of auctions if you have a video
5) Better user verification systems

Plus a lot more

Will keep you informed as we move along as I seriously believe this is the only
option we have to survive the times ahead as carrying on like this will not be
an option.

I'm in agreement with Powerseller on phpProBid sites:
Quote from: PS
I would very very very strongly dislike it if the script were changed. I do not like phpprobid sites. I don't like the listing form, and they all have an unprofessional cookie cutter appearance to me. It's like 'you've seen one phpprobid site, you've seen two thousand of them'. I do like RScript very much which is one of the main reasons why I considered listing on PlunderHere to begin with. So my $0.02 is that I would HATE IT HATE IT HATE IT!
Logged

"Well, Jay was so giddy that someone named Jay was involved with this site we posted our first non-eBay listing in 3 years here at Lunarbid (we tried two items at Yahoo once upon a time, they bombed)." -Marie posting  in a LunarBid thread at OTWA in 2005 wins the award for 'most moronic reason ever given for choosing a venue'

amy

  • You Wish You Were Me
  • LieWorld Moderator
  • Lawnmower Mouth
  • *****
  • Karma: 272
  • Offline Offline
  • Gender: Female
  • Posts: 3460
  • Member

There are a lot of complaints on the PH boards.  I don't think exchanging RScript's bugs for phpProBid's bugs is going to solve the real problem.

PowerSeller

  • Paparazzi Target ~ Beta Version
  • Full Member
  • ****
  • Karma: -116
  • Offline Offline
  • Posts: 168

There are a lot of complaints on the PH boards.  I don't think exchanging RScript's bugs for phpProBid's bugs is going to solve the real problem.

Yes, I think working through the problems would be far better than adding a whole new set of problems to the mix while wiping out some of what people like about PH now.  For PH's sake and Mark's sake, I honestly hope I'm wrong.
Logged

Atomic Mall Staff: AM Forum Moderator

regic

  • Tulip Overlord
  • Lawnmower Mouth
  • *****
  • Karma: 281
  • Offline Offline
  • Gender: Female
  • Posts: 2745
  • Bite Me!

Quote
This script 'Rscript' is very functional but very 'buggy' and this
cannot be helped as it is a natural occurrence with 'Perl type scripts.

Buggy scripts are a 'natural occurrence' when the scriptwriter is an incompetent idiot or sloppy programmer. RScript's bugs have nothing to do with the script being written in Perl.  The PHP language actually has more reported bugs, and security problems, than Perl because PHP is a newer language.  

Quote
We cannot transfer items into categories so what we would do is
have one category for all PH items and then you the user must
allocate one or two categories for your items.

translation: all 58,000 listings will need to be revised by sellers after the move

Quote from: plunderhere.eu
   This domain has just been registered for one of our customers!
Domain registration and webhosting at best prices.

When did Plunderhere.eu bite the dust?  Was any notice given of the site's closing?
Logged

sneakymagenta

  • Lawnmower Mouth
  • ********
  • Karma: 251
  • Offline Offline
  • Gender: Female
  • Posts: 2623
  • November 2nd is Buy at an IR 500 Site Day!

Quote
The man behind the curtain is going to change scripts.......

 :blinkie: :blinkie: :blinkie: :blinkie:

Man the lifeboats!

:popcorneaters:
Logged

OAI Moron Hall of Fame
sell-thru is an irrelevant and illogical consideration.
-KaRay, owner of WP giving selling advice, 2006

the site was 'NOT' hacked but the little script that had recipes on had the link altered
-Plunderhere Owner Mark Taylor after his site was hacked by a Chinese hacker gang, 2008

Some people have it like that, others don’t. I do.
-Probidscripts owner Spencer Osama Binweb Laden Ray bragging about his ability to scam the OAI without feeling any guilt, 2008.

How does an auction site get buyers?
-question asked at PSU by owner of auction site BidBeaver.ca, 2008

How do I get sales?
-question asked at PSU by online store owner, 2009.

I was told by my Tech. Support that my site dont really need SSL.. his servers
are well protected and that info your providing to join aint really top secret information

-owner of auction site TheTraderOutlet.com discussig his site's lack of basic security, 2009

mandy

  • Tulip Overlord
  • Rabble-Rouser
  • *****
  • Karma: 193
  • Offline Offline
  • Gender: Female
  • Posts: 9806
  • Memberless

Quote
When did Plunderhere.eu bite the dust?  Was any notice given of the site's closing?

It closed about 2 weeks ago:

Quote from: Plunderhere
An email was sent out as the site is going to be redone soon
but not sure everybody got the email as a few have contacted
me saying they did not get it.

We hope to have it back up soon and it will still be free for users
after the modifications have been added.

There really is not many auctions running on there but we will advise
as soon as we relaunch it.

http://www.plunderhere.com/forums/showthread.php?t=9630

BellisimaJ.

  • Advertiser
  • Rabble-Rouser
  • *
  • Karma: 148
  • Offline Offline
  • Gender: Female
  • Posts: 6602

Quote
The man behind the curtain is going to change scripts.......

 :blinkie: :blinkie: :blinkie: :blinkie:

Man the lifeboats!

:popcorneaters:


 :happy001:
Logged

xwpopper

  • Big Member
  • *****
  • Karma: 21
  • Offline Offline
  • Posts: 440

If any PH members want to know what will happen when the script changes over, it looks like Ray may have been chartered to handle the switch since he and Mo's resident "moron" can't handle the site.
http://probid.alsoshop.com/index.php?

All products will be in the same category when it is done. If it is handled correctly, the images should transfer smoothly, but have you ever tried to transfer 100K images? There will be timeouts and overloads (with the sorry PH server) and broken image files. Then, there will be those who have thousands of products listed to edit, one by one, at the same time as hundreds of other sellers. That will likely cause all kind of chaos in the database, to have in a few days, every seller change their categories, edit payment, shipping, often the description (since Probid works much differently with templates) and adds all their new features like swaps, offers, and videos. That should basically kill the site.

PS is making sense about the change, and no one seems to understand what she is saying. It seems like any cause she is fighting for, even the good ones like this, she ends up alone.

Mark has never run a site with this many listings. He already screwed up the server move royally for 2 months, and there are still prblems, but it really didn't require much skill. Now, PH members are going to trust him with a move that actually requires some skill?
Logged

"Listen up Mother****er. Try that bulls*** here and I will hand you and your head in a basket"
- Ray Romeo's alter ego Andrew Pittino responding when I signed up a new account on Wagglepop to verify the non-existence of a way to opt out of his sharing my information with third parties.
Pages: 1 ... 26 27 [28] 29 30 ... 66   Go Up
Bookmark and Share

 



powered by Apache

powered by Linuxpowered by CentOS

Copyright 2000-2008 TulipTools.com and Brixton Technology Ventures Ltd. All rights reserved.