GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   People Using Nifty Stats - you might want to check this (https://gfy.com/showthread.php?t=868837)

Machete_ 11-12-2008 02:10 PM

People Using Nifty Stats - you might want to check this
 
I tested Nifty Stats, and really liked it, and was just about to upgrade to the Pro version.

Just to test a few things I went in to the DB file and was quite shocked that all my passwords and usernames was stored in the database, UNencrypted, in a big flat file.

I dont do drama, but this is a security issue I think the users should be aware of.

The program default install path is in "C:\Documents and Settings\USERNAME\Application Data"

That folder is assessible by some Browserplugins

papill0n 11-12-2008 02:27 PM

going to check that right now

polish_aristocrat 11-12-2008 02:27 PM

not my biz, but you said you left adult...

Machete_ 11-12-2008 02:30 PM

Quote:

Originally Posted by polish_aristocrat (Post 15044438)
not my biz, but you said you left adult...

I think you should read what I wrote again

Super Negro 11-12-2008 02:39 PM

I just checked mine and it is a completely encrypted file, I can't read anything in it, all characters and jibberish

Machete_ 11-12-2008 02:45 PM

Quote:

Originally Posted by Super Negro (Post 15044505)
I just checked mine and it is a completely encrypted file, I can't read anything in it, all characters and jibberish

then send it to me - email is in the sig

Super Negro 11-12-2008 02:50 PM

Quote:

Originally Posted by ebus_dk (Post 15044543)
then send it to me - email is in the sig

nice try

margarita 11-12-2008 03:42 PM

You can change the folder but AFAIK browser plugins can read ANY files and folders on your HDD which are accessible by current user's permissions (do you keep only encrypted docs on your disk?). That's why you definitely should not install any unsigned and untrusted ActiveX and programs.
Correct me if I'm wrong but once I was using plugin in IE for uploading of photos ant it uploaded all photos I've threw to it and they were not in "application data" folder for sure :)

Lace 11-12-2008 03:44 PM

loginBLAHxpassBLAHx

yeah, pretty open...

NinjaSteve 11-12-2008 04:48 PM

At least you'd need a user/pass from what Lace is saying.

Machete_ 11-12-2008 04:52 PM

Quote:

Originally Posted by NinjaSteve (Post 15045268)
At least you'd need a user/pass from what Lace is saying.

no - that is NOT what he said, and its NOT how it is

kgp43 11-18-2008 12:58 AM

up we go

Bro Media - BANNED FOR LIFE 11-18-2008 01:13 AM

Oh damn, that sucks... :(

Hopefully Jenna sees this and they roll out an update with encryption?

Machete_ 11-18-2008 01:19 AM

Quote:

Originally Posted by Retox Josh (Post 15071144)
Oh damn, that sucks... :(

Hopefully Jenna sees this and they roll out an update with encryption?

They know it, but claim its not a issue.

They also claim that any other software out there stores the passwords unencrypted in clear text files

I dont know who Jenna from Nifty is. The Support team that answer Nifty Stats Questions, dont want to tell me their names


All times are GMT -7. The time now is 10:30 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc