ra23.net Just another WordPress weblog

11Mar/110

PHPIPS activated in this WordPress Installation

Hi,

today I started coding again on PHPIDS.

I implemented it in this wordpress installation. Each attack is logged into a mysql table and the system is in so called "kick ass mode".
So if you inject some stuff you will soon or later mess up your session.

If you reset your session you are back on 0 and can inject other attacks or just leave me a comment. :)

Feel free to play a little bit around with the search or the admin login and inject some attacks.

A low level attack e.g.

'>XXX

If you need some higher impact values try to search for

'>XXX javascript:alert(1) SELECT DISTINC ;

The coding itself was cleaning up codebase, so no new feature is in the code, just a few modified commands for mysql logging and sending mails.

I really need some attack requests and some more testing to further implement new functionality. So feel free to suggest wishes, what you would like to see or to have.
Because most coding effort is currently framework stuff, it will take some time for a new version because till now everything works quite fine.

Oh, and please don't hurt this system, or at least try to :)

Filed under: phpips Leave a comment
Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

(required)

No trackbacks yet.