Re: Web security issue help

Ravi Kumar <[email protected]>
Newsgroups gmane.user-groups.linux.delhi
Message-ID <CAPQPR+8iqqYkXJt75JK4ocM-3J45sFvHEgYdBZAURY2StnuE-A@mail.gmail.com>
Found the issue and reported to him in 121 mail. GoodNite.
On Jun 26, 2013 12:55 AM, "abhishek jain" <[email protected]>
wrote:

>
>
> > Hi,
> > we have a website http://www.brahmabooks.com which is developed in core
> > php without any framework or anything. Today someone mailed us with few
> > user details saying that he has hacked our system. Now i don't
> > understand how could someone display all details from our database. We
> > have used PHP PDO with parameterized query and have tested against lots
> > of sql injection techniques and found it injection proof. I found that
> > Cookies are not encrypted and are stored in plain data which i have to
> > take care of but is it possible to get table columns and data with this
> > detail?
> > Can someone guide me how can i secure it and how he would have got
> > these details?
> > Thanks
> >
>
> Hi Rakesh,
> First thing I will suggest is change your machine passwords. I am sure you
> must have done it by now. Have you?
>
> Thanks,
> Abhishek
>
>
> _______________________________________________
> Ilugd mailing list
> Ilugd-cunTk1MwBs8/[email protected]
> http://frodo.hserus.net/mailman/listinfo/ilugd
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.