• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

WoWonder - The Ultimate PHP Social Network Platforms

WoWonder - The Ultimate PHP Social Network Platform v4.3.3 12-29-2023

No permission to download
Hi mates, who know how to add custom pages in wowonder. Not through the admin panel. But something more customizable?
 
Guys ,



When i trying to install the latest version 4.3.3 it's gose to a blank page after I fill all the database details , please help me .
 
Has anyone ever received emails formatted in html to confirm an email or for anything? i.e. pure code?

for example like this:
Code:
<p>Hi User,<br /><br /> Please verify that it&rsquo;s you<br /><br /> Your sign in attempt seems a little different than usual. This could be because you are signing in from a different device or a different location.<br /><br /> If you are attempting to sign-in, please use the following code to confirm your identity:<br /><br /> 38355<br /><br /> Here are the details of the sign-in attempt:<br /> Date: 2024-01-02 02:33:40am<br /> Account: [email protected]< br /> Location: <br /> IP Address: 182.49.126.34<br /> City: My City<br /><br /> If this wasn't you, please reset your password.<br /><br / > Yours securely,<br /> SIte</p>

It's really very annoying and I don't know how to fix it
Nobody ?
 
  • Like
Reactions: chidexco29
I tried to send a message from contacts but only the content arrives on the email without the email information or the name and surname, solutions?
 
Hello everyone.
I have found a lot of complaints about wowonder vulnerability and a backdoor that is used to access users info on plateformes. Here are some suggestions that has been done by someone to improve. Can someone here help us do that or show how we can do that?

Here are some suggestions to improve the security and maintainability of the codebase:

1. Strengthen input validation and sanitization to prevent vulnerabilities like SQL injection and XSS.

2. Prefer prepared statements for database interactions to thwart SQL injection attacks.

3. Implement centralized authentication and authorization mechanisms for consistent access control.

4. Encapsulate access control logic for better code maintainability.

5. Minimize dynamic file inclusion based on user input and validate/sanitize inputs rigorously.

6. Enhance session management security by following best practices like rotating session IDs.

7. Implement comprehensive error handling to prevent information leakage and provide user-friendly error messages.

8. Review file system operations to prevent directory traversal attacks.

9. Conduct regular security audits and stay updated with security patches.

10. Consider implementing security headers and Content Security Policy (CSP) to mitigate client-side attacks.

These measures will enhance the overall security posture of the WoWonder application and improve user trust and satisfaction.

Best regards,
 
Hello everyone.
I have found a lot of complaints about wowonder vulnerability and a backdoor that is used to access users info on plateformes. Here are some suggestions that has been done by someone to improve. Can someone here help us do that or show how we can do that?

Here are some suggestions to improve the security and maintainability of the codebase:

1. Strengthen input validation and sanitization to prevent vulnerabilities like SQL injection and XSS.

2. Prefer prepared statements for database interactions to thwart SQL injection attacks.

3. Implement centralized authentication and authorization mechanisms for consistent access control.

4. Encapsulate access control logic for better code maintainability.

5. Minimize dynamic file inclusion based on user input and validate/sanitize inputs rigorously.

6. Enhance session management security by following best practices like rotating session IDs.

7. Implement comprehensive error handling to prevent information leakage and provide user-friendly error messages.

8. Review file system operations to prevent directory traversal attacks.

9. Conduct regular security audits and stay updated with security patches.

10. Consider implementing security headers and Content Security Policy (CSP) to mitigate client-side attacks.

These measures will enhance the overall security posture of the WoWonder application and improve user trust and satisfaction.

Best regards,
Thank you, do you maybe have some concrete files?
 
A backup conflicts with new published files and data stored on the server after the backup
There should be no conflicts if the hosting is normal. I used the backup myself without any problems if I needed it. The least that can happen is if there have been changes or updates on the site from copy to copy. In this case, a conflict may arise. I have copies made daily. If several days pass between copies, then it's up to you to either restore the administrator (abandoning the information that was added between copies), or reinstall the entire script, and in this case abandon EVERYTHING that was published.
 
  • Like
Reactions: josh13
There should be no conflicts if the hosting is normal. I used the backup myself without any problems if I needed it. The least that can happen is if there have been changes or updates on the site from copy to copy. In this case, a conflict may arise. I have copies made daily. If several days pass between copies, then it's up to you to either restore the administrator (abandoning the information that was added between copies), or reinstall the entire script, and in this case abandon EVERYTHING that was published.
Exactly. Just as I wrote before. If there is an active site which functions on a daily basis, it is important to make sure to back up the database on a daily basis and then the damage of data loss is minimal.
 
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock