Themes, Templates and Scripts

Xvideosharing 2.0 (nulled)

Submitted by xenorax, , Thread ID: 231168

Thread Closed

RE: Xvideosharing 2.0 (nulled)

AirBrush66
Lurker
Prime
Level:
0
Reputation:
0
Posts:
1
Likes:
0
Credits:
23
20-01-2022, 02:05 AM
#15
The problem is that the script has grown over the last 10-15 years and the developers unfortunately have relatively little idea about security & performance optimization. The quality of the code is very very poor (e.g. abbreviations everywhere, invalid HTML, no consistent validations, a lot of code is commented out page by page, no proper database concept, a ton of performance issues, the dead language perl as a programming language, ...).

Each of the versions that have been released in recent years have extreme gaps because, among other things, information is not validated, areas are not properly protected, Modules are not updated (e.g. ffmpeg was not updated for years and due to a gap and missing validations various sites could be hacked, or the internal password can be guessed by brute-force attacks, the internal apis are publicly accessible etc.). If you don't know anything about Perl, linux, server security and can't write regular expressions, it's better to leave it alone.

Version 2 currently has at least 3-4 security vulnerabilities which can be exploited. Whoever uses this script should also make sure that the compiled library files which are used for license management (cgi-bin/Modules/Sibsoft/*) disappear from the project (there can be anything in there, must of course be adjusted beforehand).

Users browsing this thread: 1 Guest(s)