Closed Thread
Page 1 of 3 123 LastLast
Results 1 to 15 of 31

Thread: The Hosting Tool Secure?

  1. #1
    FWS Addict raversworld is a jewel in the roughraversworld is a jewel in the rough raversworld's Avatar
    Join Date
    Oct 2006
    Location
    Philadelphia, Pennsylvania, Un
    Posts
    782

    The Hosting Tool Secure?

    So a while back I was using the hosting tool as my billing system because I was strapped for money. In which I found out that there was an exploit that came out prior to an update. My site was hacked using that exploit. This has shaken my beliefs in the security of the script itself. Should I put it back on with the most recent update?

  2. #2
    FWS Addict theraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant future theraptor's Avatar
    Join Date
    Nov 2008
    Location
    /dev/null
    Posts
    502
    The MySQL injection vulnerability you are referring (Secunia SA42369)to was kindly pointed out to us by both the finder and Secunia, and was patched in the v1.2.3 release a full week before the advisory was released to the public(the update was released 12-14-2010). The only way you should have been "hacked" by this exploit is if you have not been properly updating your script, which is entirely your fault, as THT reminds you to update every time you view the Admin CP. The only current exploit is a Cross-Site Scripting problem, which has been minimized in the current release (1.2.3) and with the proper security protocols that any webmaster should be following is not really a problem at all (log out of THT Admin CP when you are done with it, do not visit suspicious websites while logged in to the ACP)

    As with any script for your website, you should maintain caution and keep in mind that THT was, and is, intended to be used for free hosts. If you are selling hosting to someone, you should make the small investment in a system such as WHMCS, which was designed for that.
    (,,)(,,)
    (@.'.)=@ TheHostingTool - Is Better Than cPCreator - And still Free!
    (/ \) Coming Soon: MintForumSystem - A New Breed of Forum Software

  3. #3
    So I assume, it is safe for us to continue to use THT, rite?

  4. #4
    Cross Industries Schmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud of
    Join Date
    Jun 2007
    Location
    United States
    Posts
    3,416
    So your saying I can't go ahead and hack someone's site? I already reported a few more holes in your system. I think I've reported over a dozen in the past couple of updates.
    Sean Marvin Cross Industries - Affordable technology solutions Glacier Host - Affordable Web Hosting Services
    E-mail: contact@x-ind.com Phone: (843) 879-8293 Hours: Weekdays, 8AM-6PM EST; Saturday, 10AM-5PM EST

  5. #5
    FWS Addict theraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant futuretheraptor has a brilliant future theraptor's Avatar
    Join Date
    Nov 2008
    Location
    /dev/null
    Posts
    502
    Now this is interesting. Where have you reported them to Schmarvin? Certainly not using the Google Code Issue tracker. And not to my email or Kevin's also. And Secunia hasn't added any issues to the advisory database, so if you reported them there they can't be much issues at all. If you have found some security flaws, please report them to me, and they will be patched.
    (,,)(,,)
    (@.'.)=@ TheHostingTool - Is Better Than cPCreator - And still Free!
    (/ \) Coming Soon: MintForumSystem - A New Breed of Forum Software

  6. #6
    Schmarvin,
    are those holes are critical exploit?
    Please share some info.

  7. #7
    Junior Member techsavy is an unknown quantity at this point
    Join Date
    Aug 2011
    Posts
    1
    Nice, was a good read.

  8. #8
    Cross Industries Schmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud ofSchmarvin has much to be proud of
    Join Date
    Jun 2007
    Location
    United States
    Posts
    3,416
    Quote Originally Posted by theraptor View Post
    Now this is interesting. Where have you reported them to Schmarvin? Certainly not using the Google Code Issue tracker. And not to my email or Kevin's also. And Secunia hasn't added any issues to the advisory database, so if you reported them there they can't be much issues at all. If you have found some security flaws, please report them to me, and they will be patched.
    I did, right when you guys went into development. Not my fault if the issues were marked and removed.

    Quote Originally Posted by Derek Flahost View Post
    Schmarvin,
    are those holes are critical exploit?
    Please share some info.
    They were at the time.
    Sean Marvin Cross Industries - Affordable technology solutions Glacier Host - Affordable Web Hosting Services
    E-mail: contact@x-ind.com Phone: (843) 879-8293 Hours: Weekdays, 8AM-6PM EST; Saturday, 10AM-5PM EST

  9. #9
    Usually, the real legal copy can be pretty safe to serve as a hosting tool!
    dvd-flv Spreading the sky. O(∩_∩)ONo one is not an angel!

  10. #10
    Quote Originally Posted by schwaface View Post
    Usually, the real legal copy can be pretty safe to serve as a hosting tool!
    Explain "real legal copy".
    THT is an open source script, so it is a legal copy, no matter how we download it.

  11. #11
    b& Tc-Ltd has a little shameless behaviour in the past
    Join Date
    Oct 2011
    Posts
    9
    take it from me
    THT is secured we are working with a small hacker team to test security on it
    93% is safe
    but 7% still need some changement

  12. #12
    b& deeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant futuredeeplist has a brilliant future deeplist's Avatar
    Join Date
    Dec 2001
    Location
    Auburn, IN - USA
    Posts
    3,168
    Quote Originally Posted by Tc-Ltd View Post
    93% is safe
    but 7% still need some changement
    Do you have a source for these stats, or do you only get hacked 7% of the time?

  13. #13
    WP Like sander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to behold sander k's Avatar
    Join Date
    Jan 2008
    Location
    Netherlands
    Posts
    2,234
    Quote Originally Posted by Tc-Ltd View Post
    take it from me
    THT is secured we are working with a small hacker team to test security on it
    93% is safe
    but 7% still need some changement
    Are you with THT?
    Who are you?
    Opening soon WP Like!

  14. #14
    cs-squad.net CS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud ofCS Squad has much to be proud of CS Squad's Avatar
    Join Date
    Dec 2009
    Location
    Where Else? My /home
    Posts
    1,752
    Quote Originally Posted by Tc-Ltd View Post
    take it from me
    THT is secured we are working with a small hacker team to test security on it
    93% is safe
    but 7% still need some changement
    7% is quite high actually.

  15. #15
    WP Like sander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to beholdsander k is a splendid one to behold sander k's Avatar
    Join Date
    Jan 2008
    Location
    Netherlands
    Posts
    2,234
    I was thinking of installing THT, but nevermind.
    Opening soon WP Like!

Closed Thread

Similar Threads

  1. New The Hosting Tool Design
    By JonnyH in forum Review my webdesign
    Replies: 25
    Last Post: January 2nd, 2009, 18:36
  2. THT - The Hosting Tool
    By JonnyH in forum Programming Help
    Replies: 58
    Last Post: December 23rd, 2008, 04:47
  3. Replies: 0
    Last Post: December 7th, 2008, 14:58
  4. The Hosting Tool Main Website
    By JonnyH in forum Review my webdesign
    Replies: 2
    Last Post: December 4th, 2008, 13:55

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts