=========================================================== .___ __ __ _________________ __ __ __| _/|__|/ |_ / ___\_` __ \__ \ | | \/ __ | | \\_ __\ / /_/ > | \// __ \| | / /_/ | | || | \___ /|__| (____ /____/\____ | |__||__| /_____/ \/ \/ grep rough audit - static analysis tool v2.8 written by @Wireghoul =================================[justanotherhacker.com]=== between-6+dfsg1/game7/server/server.php-517- between-6+dfsg1/game7/server/server.php:518: $result = mysql_query( $query ); between-6+dfsg1/game7/server/server.php-519- ############################################## between-6+dfsg1/game7/server/server.php-603- $query = "SELECT * FROM $tableNamePrefix"."games ". between-6+dfsg1/game7/server/server.php:604: "WHERE game_id = '$game_id' AND player_1_id != '$player_id' ". between-6+dfsg1/game7/server/server.php-605- "AND player_2_ready = '0';"; ############################################## between-6+dfsg1/game7/server/server.php-622- "player_2_touch_date = CURRENT_TIMESTAMP " . between-6+dfsg1/game7/server/server.php:623: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-624- ############################################## between-6+dfsg1/game7/server/server.php-689- "player_2_touch_date = CURRENT_TIMESTAMP " . between-6+dfsg1/game7/server/server.php:690: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-691- ############################################## between-6+dfsg1/game7/server/server.php-756- $query = "SELECT * FROM $tableNamePrefix"."games ". between-6+dfsg1/game7/server/server.php:757: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-758- $result = gs_queryDatabase( $query ); ############################################## between-6+dfsg1/game7/server/server.php-778- "touch_date = CURRENT_TIMESTAMP " . between-6+dfsg1/game7/server/server.php:779: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-780- ############################################## between-6+dfsg1/game7/server/server.php-818- "$playerTouchDateName = CURRENT_TIMESTAMP " . between-6+dfsg1/game7/server/server.php:819: "WHERE game_id = '$game_id' ". between-6+dfsg1/game7/server/server.php-820- "AND game_passcode = '$game_passcode';"; ############################################## between-6+dfsg1/game7/server/server.php-877- $query = "SELECT * FROM $tableNamePrefix"."games ". between-6+dfsg1/game7/server/server.php:878: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode' ". between-6+dfsg1/game7/server/server.php-879- "FOR UPDATE;"; ############################################## between-6+dfsg1/game7/server/server.php-938- "changed_in_state = '$state_number' " . between-6+dfsg1/game7/server/server.php:939: "WHERE game_id = '$game_id' AND ". between-6+dfsg1/game7/server/server.php-940- "column_index = '$column_index';"; ############################################## between-6+dfsg1/game7/server/server.php-953- "state_number = '$state_number' " . between-6+dfsg1/game7/server/server.php:954: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-955- ############################################## between-6+dfsg1/game7/server/server.php-1021- $query = "SELECT * FROM $tableNamePrefix"."games ". between-6+dfsg1/game7/server/server.php:1022: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-1023- $result = gs_queryDatabase( $query ); ############################################## between-6+dfsg1/game7/server/server.php-1050- $query = "SELECT * FROM $tableNamePrefix"."columns ". between-6+dfsg1/game7/server/server.php:1051: "WHERE game_id = '$game_id' AND ". between-6+dfsg1/game7/server/server.php-1052- "changed_in_state > $last_state_seen;"; ############################################## between-6+dfsg1/game7/server/server.php-1088- "$playerTouchDateName = CURRENT_TIMESTAMP " . between-6+dfsg1/game7/server/server.php:1089: "WHERE game_id = '$game_id' AND game_passcode = '$game_passcode';"; between-6+dfsg1/game7/server/server.php-1090- gs_queryDatabase( $query ); ############################################## between-6+dfsg1/game7/server/server.php-1253- between-6+dfsg1/game7/server/server.php:1254: $result = mysql_query( $inQueryString ) between-6+dfsg1/game7/server/server.php-1255- or gs_fatalError( "Database query failed:<BR>$inQueryString<BR><BR>" . ############################################## between-6+dfsg1/minorGems/network/unix/SocketUDPUnix.cpp-121- // try converting it from aaa.bbb.ccc.ddd between-6+dfsg1/minorGems/network/unix/SocketUDPUnix.cpp:122: int convertedAddress = inet_addr( inAddress ); between-6+dfsg1/minorGems/network/unix/SocketUDPUnix.cpp-123- ############################################## between-6+dfsg1/minorGems/network/linux/gnut_net.c-88- } between-6+dfsg1/minorGems/network/linux/gnut_net.c:89: if ((sinptr = get_if_addr(iface))==NULL) { between-6+dfsg1/minorGems/network/linux/gnut_net.c-90- g_debug(1,"Can't get local IP address through interface, trying host name...\n"); ############################################## between-6+dfsg1/minorGems/network/linux/SocketClientLinux.cpp-236- // this is obsolete on linux between-6+dfsg1/minorGems/network/linux/SocketClientLinux.cpp:237: // saddr.s_addr = inet_addr( inAddress ); between-6+dfsg1/minorGems/network/linux/SocketClientLinux.cpp-238- ############################################## between-6+dfsg1/minorGems/network/linux/SocketLinux.cpp-352- // between-6+dfsg1/minorGems/network/linux/SocketLinux.cpp:353: // struct hostent *host = gethostbyaddr( (char *) &sin.sin_addr, between-6+dfsg1/minorGems/network/linux/SocketLinux.cpp-354- // sizeof sin.sin_addr, ############################################## between-6+dfsg1/minorGems/network/linux/gnut_lib.h-88- between-6+dfsg1/minorGems/network/linux/gnut_lib.h:89:#define inet_aton(string, ip) (ip)->s_addr = inet_addr(string) between-6+dfsg1/minorGems/network/linux/gnut_lib.h-90- ############################################## between-6+dfsg1/minorGems/network/win32/SocketWin32.cpp-398- // between-6+dfsg1/minorGems/network/win32/SocketWin32.cpp:399: // struct hostent *host = gethostbyaddr( (char *) &sin.sin_addr, between-6+dfsg1/minorGems/network/win32/SocketWin32.cpp-400- // sizeof sin.sin_addr, ############################################## between-6+dfsg1/minorGems/network/win32/HostAddressWin32.cpp-155- between-6+dfsg1/minorGems/network/win32/HostAddressWin32.cpp:156: unsigned long returnedValue = inet_addr( mAddressString ); between-6+dfsg1/minorGems/network/win32/HostAddressWin32.cpp-157- ############################################## between-6+dfsg1/minorGems/network/win32/SocketClientWin32.cpp-186- /* First try it as aaa.bbb.ccc.ddd. */ between-6+dfsg1/minorGems/network/win32/SocketClientWin32.cpp:187: saddr.s_addr = inet_addr( inAddress ); between-6+dfsg1/minorGems/network/win32/SocketClientWin32.cpp-188- if( saddr.s_addr != INADDR_NONE ) { ############################################## between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheckAnalyze-2- between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheckAnalyze:3:CHECKER=`dirname $0`/LeakCheck" $@" between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheckAnalyze:4:ANALYZER=`dirname $0`/leak-analyze" $1 leak.out" between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheckAnalyze-5- ############################################## between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheck-9-# needs: between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheck:10:SHLIB=`dirname $0`/LeakTracer.so between-6+dfsg1/minorGems/util/development/leakTracer/LeakCheck-11-if [ ! -x $SHLIB ] ; then ############################################## between-6+dfsg1/minorGems/protocol/p2p/notes.tex-36- between-6+dfsg1/minorGems/protocol/p2p/notes.tex:37:For a more complex example, consider the case where $r$ is a search results set. Note that a search is itself a resource that might be offered by a host, and we might have specially-designated index nodes in the network that offer the resource of searching. Suppose $A$ sends $D_r$ to $B$. $D_r$ might contain information about the resource types to search for, as well as a set of resource descriptors. Suppose that $B$ does not have the capability to perform the requested search, but is aware of a super-node $B'$ that does have searching capabilities. $B$ has two options at this point: return a description of $B'$, or forward $D_r$ to $B'$. Since the method of executing the first option is obvious, consider the second option. $B$ forwards $D_r$ to $B'$, and $A$ waits for a response. $B'$ performs the search, constructing the set $R = \{D_{r'} \mid r'$ matches the search criteria of $r \}$. $B'$ attaches the identifier from $D_r$ to $R$ and then sends it to the return address found in $D_r$. $A$ receives $R$. By examining the identifier, $A$ knows $R$ is a response to $D_r$. between-6+dfsg1/minorGems/protocol/p2p/notes.tex-38-