el_makong
Hosting Guru
mau tanya,apa ada pengaturan untuk ngelimit user buat ngerubah detail?
jadi misalnya ada user baru register,musti d approve dulu baru bisa pake layanan apapun...
trus kalo user mau change detail juga harus d periksa...
settingannya dimana ya?
soalnya dapet jatah inject nih kyknya...
jadi barusan saya revert database n lsg update ke 5.2.12..untung blom ada active order minggu ini...>.<
tambahan,sempet ada user register pake email [email protected] n kyknya langsung exploit..kalo ada yg kenal,hajar plz...tq
jadi misalnya ada user baru register,musti d approve dulu baru bisa pake layanan apapun...
trus kalo user mau change detail juga harus d periksa...
settingannya dimana ya?
soalnya dapet jatah inject nih kyknya...
Code:
Client ID: 11 - hos hosting has requested to change his/her details as indicated below:
First Name: 'hos' to 'AES_ENCRYPT(1,1), firstname=(SELECT GROUP_CONCAT(id,0x3a,username,0x3a,email,0x3a,password SEPARATOR 0x2c20) FROM tbladmins)'
Last Name: 'hosting' to '1'
Company Name: 'hosting' to '1'
Address 1: 'surabaya' to '1'
Address 2: 'surabaya' to '1'
City: 'surabaya' to '1'
State: 'jawa timur' to '1'
Postcode: '036' to '1'
Country: 'ID' to 'US'
Phone Number: '085637282644' to '1'
Default Payment Method: '' to ''
If you are unhappy with any of the changes, you need to login and revert them - this is the only record of the old details.
jadi barusan saya revert database n lsg update ke 5.2.12..untung blom ada active order minggu ini...>.<
tambahan,sempet ada user register pake email [email protected] n kyknya langsung exploit..kalo ada yg kenal,hajar plz...tq