inherit
54640
0
Jul 2, 2019 10:52:15 GMT -8
Phrate
It's been 9 years!
1,297
August 2005
ghotherkill
|
Post by Phrate on Dec 10, 2009 18:52:29 GMT -8
i found some security flaws And apparently you downed the whole website. Please change it back. Edit: Seems to be only on Safari
|
|
inherit
12045
0
Nov 19, 2012 14:52:05 GMT -8
Renegade
As unique as mice pudding milkshake
40,557
August 2003
renegade
|
Post by Renegade on Dec 10, 2009 18:59:58 GMT -8
i didnt do anything that major
|
|
inherit
54640
0
Jul 2, 2019 10:52:15 GMT -8
Phrate
It's been 9 years!
1,297
August 2005
ghotherkill
|
Post by Phrate on Dec 11, 2009 16:14:33 GMT -8
Yeah, nevermind. Had to do with my reputation feature, I guess.
|
|
inherit
96206
0
Apr 8, 2024 11:48:08 GMT -8
S|P|L|A|T
1,324
January 2007
splatcatballa99
|
Post by S|P|L|A|T on Dec 11, 2009 20:32:07 GMT -8
lol so you ip banned me for finding an exploit in your forum? I didn't do anything malicious with it... shows your maturity level.
|
|
inherit
54640
0
Jul 2, 2019 10:52:15 GMT -8
Phrate
It's been 9 years!
1,297
August 2005
ghotherkill
|
Post by Phrate on Dec 12, 2009 4:12:38 GMT -8
I didn't ban you.. I was informed that one of my staff members just wanted to see if you were any good at what you were doing, so they banned you, tempting you to get back in I guess?
|
|
inherit
123128
0
Feb 3, 2020 13:53:38 GMT -8
Malagrond
Remember, remember the 5th of November.
813
April 2008
malagrond
|
Post by Malagrond on Dec 17, 2009 8:44:10 GMT -8
I know your site warns that it's best viewed in Internet Explorer, but this with Safari? I'll try to test some injections for ya too. ~Mala
|
|
inherit
54640
0
Jul 2, 2019 10:52:15 GMT -8
Phrate
It's been 9 years!
1,297
August 2005
ghotherkill
|
Post by Phrate on Dec 18, 2009 8:21:58 GMT -8
Yes, that's with just about any browser besides IE. But, a fellow named Luke is going to help make it cross-browser.
And, that's not necessary. In fact, I'd appreciate it if everyone stopped trying.
|
|
inherit
130228
0
Jul 11, 2024 19:19:59 GMT -8
Charles Stover
1,731
August 2008
gamechief
|
Post by Charles Stover on Dec 18, 2009 11:34:44 GMT -8
It's better someone find it now than a member who's intent is malicious.
|
|
inherit
12045
0
Nov 19, 2012 14:52:05 GMT -8
Renegade
As unique as mice pudding milkshake
40,557
August 2003
renegade
|
Post by Renegade on Dec 18, 2009 13:04:11 GMT -8
you still haven't fixed the major flaw i found last week, or even disabled the way I was using it. do you need a demonstration of the damage I could do with it before you decide its worth changing?
|
|
#00AF33
14306
0
1
Sept 8, 2023 8:54:17 GMT -8
Jordan
What is truth?
11,838
October 2003
jab2
|
Post by Jordan on Dec 19, 2009 17:28:43 GMT -8
you still haven't fixed the major flaw i found last week, or even disabled the way I was using it. do you need a demonstration of the damage I could do with it before you decide its worth changing? What is the exploit that you did? I did some messing around on the forum, but since I'm not very knowledgeable about common exploits I didn't find anything before I was banned. I'm not going to be going back on the forum, but I plan on making a simple website in the future and I'm just wondering what the common injections are. I saw that you made a post and then modified it to remove the exploit. What exactly did you do? Did you just put a Javascript code in it?
|
|
inherit
100824
0
May 13, 2012 5:37:49 GMT -8
Michael
14,585
March 2007
wrighty
|
Post by Michael on Dec 21, 2009 8:38:07 GMT -8
Would be rather handy for coders if common exploits were listed etc...
|
|
inherit
12045
0
Nov 19, 2012 14:52:05 GMT -8
Renegade
As unique as mice pudding milkshake
40,557
August 2003
renegade
|
Post by Renegade on Dec 21, 2009 12:35:12 GMT -8
yeah, that's a good plan, i'll just post here how to wreck his forum. oh wait - that's not a good plan at all
|
|
inherit
112533
0
Dec 8, 2022 0:53:44 GMT -8
Luke
2,993
October 2007
darkzer0
|
Post by Luke on Dec 21, 2009 16:47:17 GMT -8
|
|
inherit
hi
65816
0
Dec 19, 2020 21:47:21 GMT -8
Ryan
Yo.
4,431
December 2005
eliasfong
|
Post by Ryan on Dec 23, 2009 14:37:40 GMT -8
Remember when Renegade, Martyn, and Pat Clinger came and had fun with some guy's web app that was full of security holes?
|
|
#00AF33
Bark Different.
102833
0
1
Feb 12, 2023 16:57:46 GMT -8
RedBassett
I'm a Marxist/Lennonist of the Groucho/John variety.
15,405
April 2007
applecomputer
RedBassett's Mini-Profile
|
Post by RedBassett on Dec 27, 2009 9:09:37 GMT -8
Common suggestion:
Do not tell someone when they (fail to) login if it is the username or password that they have wrong. This makes it easier to guess at the login, especially under some circumstances.
|
|