[BULK] RE: [WebDNA] [BULK] Should I be worried about this web traffic?

This WebDNA talk-list message is from

2017


It keeps the original formatting.
numero = 113519
interpreted = N
texte = 1114 This is a multipart message in MIME format. ------=_NextPart_000_03ED_01D2A801.F1310140 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Thanks Stuart- Yes I put a [protect admin] in there. But couldn't a bot just post the username and password to the dialog and still get in? I guess if I just change the password in my app I'd be OK? Thanks, Will From: Stuart Tremain [mailto:webdna@idfk.com.au] Sent: Tuesday, March 28, 2017 8:08 PM To: WebDNA Talk List Subject: Re: [WebDNA] [BULK] Should I be worried about this web traffic? Importance: Low Looks like you have fixed it, I just get UNAUTHORIZED. Kind regards Stuart Tremain Pharoah Lane Software AUSTRALIA webdna@idfk.com.au On 29 Mar 2017, at 11:52, William J. Starck, DDS > wrote: Hello- I have a WebDNA template index.dna that is located at http:// licensing.etherware.com The template has a [replace] like so:
[formvariables show=T] [name]=[value]
[replace db=/dbs/licenses.db&eqipaddressdatarq=[ipaddress]&append=T&autonumber=indexn um]ipaddress=[ipaddress]&[name]=[value]&last_reported=[date][/replace] [/formvariables]
This page has data posted to it from one of my Windows Apps along with the IP address of the PC posting the data. The curious thing is, I keep having blank data (with the exception of the IP address 185.57.81.38) that keeps getting written to my db. I can hit the page with a web browser and nothing happens. Should I be worried? I am concerned that whatever it is has the correct username and password. I suppose it's possible someone decompiled my C# app to get the username and password. Here is what the lighttpd log shows: 185.57.81.38 licensing.etherware.com - [24/Mar/2017:04:45:20 -0500] "GET /index.dna?username=correctusername&password=correctpassword HTTP/1.1" 200 406 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" What do you guys think? Will --------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list >. To unsubscribe, E-mail to: > archives: http://mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us --------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us ------=_NextPart_000_03ED_01D2A801.F1310140 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

Thanks = Stuart-

 

Yes I put a = [protect admin] in there. But couldn’t a bot just post the = username and password to the dialog and still get = in?

 

I guess if I = just change the password in my app I’d be = OK?

 

Thanks,<= /o:p>

 

Will

 

From:<= /b> = Stuart Tremain [mailto:webdna@idfk.com.au]
Sent: Tuesday, = March 28, 2017 8:08 PM
To: WebDNA Talk List = <talk@webdna.us>
Subject: Re: [WebDNA] [BULK] Should I = be worried about this web traffic?
Importance: = Low

 

Looks like = you have fixed it, I just get UNAUTHORIZED.

 

 

= Kind regards

=  

= Stuart Tremain

= Pharoah Lane Software

= AUSTRALIA

=  

=  

 

 

 

On 29 Mar 2017, at 11:52, William J. Starck, DDS = <wjs@drstarck.com> = wrote:

 

Hello-

I have a WebDNA template index.dna that = is located at http://
licensing.etherware.com
The template has a [replace] like so:

<FORM NAME =3D = "ODVersionNum" METHOD =3D "POST" ACTION = =3D
"http://licensing.etherw= are.com/index.dna">
[formvariables = show=3DT]
[name]=3D[value]<BR>
<INPUT TYPE =3D = "HIDDEN" NAME =3D "[name]" VALUE =3D = "[value]">
[replace
db=3D/dbs/licenses.db&eqipaddr= essdatarq=3D[ipaddress]&append=3DT&autonumber=3Dindexn
um]ipad= dress=3D[ipaddress]&[name]=3D[value]&last_reported=3D[date][/repl= ace]
[/formvariables]
</FORM>

This page has data = posted to it from one of my Windows Apps along with the
IP address of = the PC posting the data.

The curious thing is, I keep having = blank data (with the exception of the IP
address 185.57.81.38) that = keeps getting written to my db. I can hit the
page with a web browser = and nothing happens.

Should I be worried? I am concerned that = whatever it is has the correct
username and password. I suppose it's = possible someone decompiled my C# app
to get the username and = password.

Here is what the lighttpd log = shows:

185.57.81.38 licensing.etherware.com - = [24/Mar/2017:04:45:20 -0500] = "GET
/index.dna?username=3Dcorrectusername&password=3Dcorrect= password HTTP/1.1" 200
406 "-" "Mozilla/5.0 = (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"

What = do you guys = think?

Will

-----------------------------------------------= ----------
This message is sent to you because you are subscribed = to
the mailing list <talk@webdna.us>.
To = unsubscribe, E-mail to: <talk-leave@webdna.us>
arch= ives: http://mail.webdna.us/= list/talk@webdna.us
Bug Reporting: support@webdna.us

 

-------------------------------------------------------= -- This message is sent to you because you are subscribed to the mailing = list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/= list/talk@webdna.us Bug Reporting: support@webdna.us

--------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us ------=_NextPart_000_03ED_01D2A801.F1310140-- . Associated Messages, from the most recent to the oldest:

    
  1. Re: [BULK] RE: [WebDNA] [BULK] Should I be worried about this web traffic? ("WJ Starck, DDS" 2017)
  2. [BULK] RE: [WebDNA] [BULK] Should I be worried about this web traffic? ("William J. Starck, DDS" 2017)
1114 This is a multipart message in MIME format. ------=_NextPart_000_03ED_01D2A801.F1310140 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Thanks Stuart- Yes I put a [protect admin] in there. But couldn't a bot just post the username and password to the dialog and still get in? I guess if I just change the password in my app I'd be OK? Thanks, Will From: Stuart Tremain [mailto:webdna@idfk.com.au] Sent: Tuesday, March 28, 2017 8:08 PM To: WebDNA Talk List Subject: Re: [WebDNA] [BULK] Should I be worried about this web traffic? Importance: Low Looks like you have fixed it, I just get UNAUTHORIZED. Kind regards Stuart Tremain Pharoah Lane Software AUSTRALIA webdna@idfk.com.au On 29 Mar 2017, at 11:52, William J. Starck, DDS > wrote: Hello- I have a WebDNA template index.dna that is located at http:// licensing.etherware.com The template has a [replace] like so:
[formvariables show=T] [name]=[value]
[replace db=/dbs/licenses.db&eqipaddressdatarq=[ipaddress]&append=T&autonumber=indexn um]ipaddress=[ipaddress]&[name]=[value]&last_reported=[date][/replace] [/formvariables]
This page has data posted to it from one of my Windows Apps along with the IP address of the PC posting the data. The curious thing is, I keep having blank data (with the exception of the IP address 185.57.81.38) that keeps getting written to my db. I can hit the page with a web browser and nothing happens. Should I be worried? I am concerned that whatever it is has the correct username and password. I suppose it's possible someone decompiled my C# app to get the username and password. Here is what the lighttpd log shows: 185.57.81.38 licensing.etherware.com - [24/Mar/2017:04:45:20 -0500] "GET /index.dna?username=correctusername&password=correctpassword HTTP/1.1" 200 406 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" What do you guys think? Will --------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list >. To unsubscribe, E-mail to: > archives: http://mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us --------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us ------=_NextPart_000_03ED_01D2A801.F1310140 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

Thanks = Stuart-

 

Yes I put a = [protect admin] in there. But couldn’t a bot just post the = username and password to the dialog and still get = in?

 

I guess if I = just change the password in my app I’d be = OK?

 

Thanks,<= /o:p>

 

Will

 

From:<= /b> = Stuart Tremain [mailto:webdna@idfk.com.au]
Sent: Tuesday, = March 28, 2017 8:08 PM
To: WebDNA Talk List = <talk@webdna.us>
Subject: Re: [WebDNA] [BULK] Should I = be worried about this web traffic?
Importance: = Low

 

Looks like = you have fixed it, I just get UNAUTHORIZED.

 

 

= Kind regards

=  

= Stuart Tremain

= Pharoah Lane Software

= AUSTRALIA

=  

=  

 

 

 

On 29 Mar 2017, at 11:52, William J. Starck, DDS = <wjs@drstarck.com> = wrote:

 

Hello-

I have a WebDNA template index.dna that = is located at http://
licensing.etherware.com
The template has a [replace] like so:

<FORM NAME =3D = "ODVersionNum" METHOD =3D "POST" ACTION = =3D
"http://licensing.etherw= are.com/index.dna">
[formvariables = show=3DT]
[name]=3D[value]<BR>
<INPUT TYPE =3D = "HIDDEN" NAME =3D "[name]" VALUE =3D = "[value]">
[replace
db=3D/dbs/licenses.db&eqipaddr= essdatarq=3D[ipaddress]&append=3DT&autonumber=3Dindexn
um]ipad= dress=3D[ipaddress]&[name]=3D[value]&last_reported=3D[date][/repl= ace]
[/formvariables]
</FORM>

This page has data = posted to it from one of my Windows Apps along with the
IP address of = the PC posting the data.

The curious thing is, I keep having = blank data (with the exception of the IP
address 185.57.81.38) that = keeps getting written to my db. I can hit the
page with a web browser = and nothing happens.

Should I be worried? I am concerned that = whatever it is has the correct
username and password. I suppose it's = possible someone decompiled my C# app
to get the username and = password.

Here is what the lighttpd log = shows:

185.57.81.38 licensing.etherware.com - = [24/Mar/2017:04:45:20 -0500] = "GET
/index.dna?username=3Dcorrectusername&password=3Dcorrect= password HTTP/1.1" 200
406 "-" "Mozilla/5.0 = (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"

What = do you guys = think?

Will

-----------------------------------------------= ----------
This message is sent to you because you are subscribed = to
the mailing list <talk@webdna.us>.
To = unsubscribe, E-mail to: <talk-leave@webdna.us>
arch= ives: http://mail.webdna.us/= list/talk@webdna.us
Bug Reporting: support@webdna.us

 

-------------------------------------------------------= -- This message is sent to you because you are subscribed to the mailing = list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/= list/talk@webdna.us Bug Reporting: support@webdna.us

--------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us ------=_NextPart_000_03ED_01D2A801.F1310140-- . "William J. Starck, DDS"

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

WebCat2b13MacPlugIn - [shownext method=post] ??? (1997) Not seeing cart info on Invoice.tmpl (was PROBLEM) (1997) pc (1997) [OT] Brain Switching (2004) WebCat2: Items xx to xx shown, etc. (1997) Playin Tricks (2006) Announce: WebMerchant 3.0 for Mac shipping now (1998) OT: Way off-topic: Qmail and Linux (2003) database performance/design question (2000) greater than or equal to (1997) Problem with updating to 2.1.1 (1998) Cart Question (1998) Search returns all, not 20 (1997) Just a thought (1998) OS X permissions to write to Globals directory (2003) WebCat2 - storing unformatted date data? (1997) Alais Shopping Cart Directory (1998) WebCatalog 2.1b3 - Plugin or cgi ? (1997) ExclusiveLock (2000) customers getting same cart (2004)