»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 07-25-2003, 10:02 PM   #1 (permalink)
Registered User
 
phlatline's Avatar
 
Join Date: Jul 2003
Location: Midwest
Posts: 109
phlatline is on a distinguished road
Gaming IBuySpy Insecure!

I don't kno if any r aware of this, but thanx 2 Papa Doc, I now am & thought I'd spread the word.
For those unfamilar IBuySpy is a framework 4 a webbased portal app, that many use 2 run sites/w. Amongst other things there is a serious prob in the users reg mod (register.aspx).
"If a user tries to register/create an account with an email address that is already in the database, the registration module will log the user on as the account belonging to the email address, regardless of the name, password, or other information supplied!"
Now, what that means is that if a person registers w/email address of an admin, that person now has full admin rights! That person can now add/edit/del almost all content on the site, plus give access2 the user database which passwords r in pain text.
2 fix this;
Admin/Register.aspx.vb
Now, look 4 the line that calls the "AddUser" function, change 2 this:
If accountSystem.AddUser(Name.Text, FName.Text, LName.Text, Reference.Text, Email.Text, Password.Text) } 0 Then
It's 2 my understanding that that will fix the prob, but be fore warned. IBuySpy is an insecure app!
For more input check out 2600 spring issue, Papa Doc has a VBScript for this prob that's worth checking out.

phlatline is offline   Reply With Quote
Old 07-28-2003, 06:35 AM   #2 (permalink)
Registered User
 
omalleytrading's Avatar
 
Join Date: Apr 2003
Location: Albany, NY
Posts: 425
omalleytrading is on a distinguished road
How is IBuySpy otherwise?

I'm looking for portal software for an existing site, and the ASP / ASP.net choices are quite slim. Is IBuySpy a solid, feature-rich option?
omalleytrading is offline   Reply With Quote
Old 07-28-2003, 10:30 AM   #3 (permalink)
Registered User
 
phlatline's Avatar
 
Join Date: Jul 2003
Location: Midwest
Posts: 109
phlatline is on a distinguished road
It appears 2 b. One way 2 c 4 urself is 2 run a google on DesktopDefault.asp, which should yeild dozens 4 u 2 check out. If u decide 2 go w/IBuySpy, b sure 2 fix the flaws I mentioned.
Phlatline
__________________
"It's not mankind I don't like, it's the people."
phlatline is offline   Reply With Quote
Old 07-28-2003, 01:46 PM   #4 (permalink)
Registered User
 
omalleytrading's Avatar
 
Join Date: Apr 2003
Location: Albany, NY
Posts: 425
omalleytrading is on a distinguished road
Given that criteria, it looks like not many sites are using it. The first three pages of google all point to the same site....
omalleytrading is offline   Reply With Quote
Old 07-29-2003, 09:47 AM   #5 (permalink)
Registered User
 
phlatline's Avatar
 
Join Date: Jul 2003
Location: Midwest
Posts: 109
phlatline is on a distinguished road
I hear mainly small businesses. I've also heard that more peeps r starting 2 use this as well.
My point is that if any1 on this forum uses (or knows any1 who does) this app needs 2 have it fixed. W/so many members I felt the odds likely. & I do hope it helps sum1.
__________________
"It's not mankind I don't like, it's the people."
phlatline is offline   Reply With Quote
Old 07-30-2003, 03:18 PM   #6 (permalink)
Registered User
 
omalleytrading's Avatar
 
Join Date: Apr 2003
Location: Albany, NY
Posts: 425
omalleytrading is on a distinguished road
For anyone who may stumble across this thread in the future -- I downloaded and installed the DotNetNuke Portal this week. It's based on IBuySpy, and so far, I think it's fantastic. Strong feature set, and a good support base from the community.
omalleytrading is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 05:52 AM.