Frank’s weirdo cousin Trey just posted this at the Warrior Forum regarding the Good Karma List Machine script:
Trey Smith here, Frank’s business partner and younger (and better looking) cousin.
Here’s an update on the software
After talking with our Developers ALL DAY yesterday about this, we came to find out this script does NOT have the php exploit issue that one blogger is claiming.
The developers use a templating system called “Smarty” that has security measures in the header.php script that is loaded at the BEGINNING of every page on the Good Karma List Machine website.
————– From the developers ————–
“We use Smarty, a well known templating system, that at the header changes all $_GET and $_POST to use a function called ‘security’ to do scraping. It does the same thing as doing the change against sql injection”
The reason some people missed this is because it’s in the HEADER.PHP file… not in the other files (Because header.php is loaded BEFORE anything else).
However, just to be absolutely sure, we tested this using several online tools such as:
:: SQL Injection Vulnerability Test :: Online Tools
Online Vulnerability Scanning, includes Nessus, Nmap, Nikto, Joomla, DNS, OpenVas and SQLiX
In all our testing the results came back with no security issues found.
However being skeptical as we are, since your privacy is our main concern, we signed up with a service called Beyond Security, much like McAfee HackerSafe this system scans our code and shows any issues. Again this system came back with no security issues found.
This is due in part to a base engine we use in our script that automatically secures the code by locking in at low level and removing and scraping all malicious attempts to hack a site. This engine is used by many of the free websites available today, including many of the scripts offered by Blue Host.
————– END From the developers ————–
So, that’s the deal with this alleged “exploit”.
We are adding a second level of security (on top of the existing security which has passed multiple third party inspections) as well, however, just to give everyone additional peace of mind.
We’ve also fixed a bug that was preventing some people from accessing their admin panel.
(Hey – not bad turnaround on bug fixes considering we’re in the middle of a launch and we’ve never released software before! Take THAT Microsoft and Oracle (lol).)
Oh – and the reason we recommended bluehost and aweber is simple, we had THOUSANDS of downloads of this free software.
Supporting all the Autoresponder and Hosting companies would have been a nightmare.
So we chose Aweber because most people are familiar with them and they have a $1 trial right now.
We chose Buehost because they are newbie friendly.
So we stayed with the two easiest services we knew of to use
We have NO FINANCIAL AFFILIATION with either. You’ll notice there are no affiliate links from us where we’ll be compensated for sending them referrals.
The purpose of this software is to help people and contribute to our community (and to fuel our launch, obviously) …not to make a few nickles and dimes off of affiliate commissions.
Anyway – we’ll be releasing the updates after our launch tomorrow.
For now, it looks like its safe to use the software as-is.
Thanks,
Trey