I have a new Demo site in place and need a security check done on it.
I need to know if a "hacker" can break in and be malicious, so I would ask that if you have a sense of "challenge" for that sort of thing, please go to the site and see if you can cause a little insight into this software's security.
I'd be interested in seeing if there can be the usual tricks played against it, like DB injections, or a cross-site scripting done to it, the usual checks to see how the security is on the package.

BUT NOT IN A DAMAGING WAY, please and thanks.

I only need an indications to the Forums security, so I will actually lower some settings such that there will be posting allowed for guests for most of the Forums, and you don't need to register to get in... Simply test "all the usual things", stuff that the script kiddies will try..., please.

The site is at http://jlhaslip.com/aef_103_demo/.

*** Credits if you can get in and prove a cross-site scripting event, or a DB injection, and prove it was you that did it.... ***

*** Bonus credits for providing a solution to the attack you performed ***

 

 

 


Reply