Go Back   Download Forums > Downloads > Spam Chat

Closed Thread
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 11-24-2004, 02:23 PM
Rael Rael is offline
myyyyy preeeeciooous
 
Join Date: Jan 1970
Posts: 18,055
Send a message via AIM to Rael Send a message via MSN to Rael
Default

bump
__________________
<smallfont>\"I\'ll show you politics in America. Here it is, right here. \'I think the puppet on the right shares my beliefs.\' \'I think the puppet on the left is more to my liking.\' \'Hey, wait a minute, there\'s one guy holding out both puppets!\'\"
  #12 (permalink)  
Old 11-24-2004, 02:39 PM
Edmunds's Avatar
Edmunds Edmunds is offline
Administrator
 
Join Date: Mar 2004
Posts: 19,347
Default

It's a common exploit. This is why $_GET data should rarely be used for queries.

There's 2 problems
1. Remember that this is invision free and they most likely have that bug fixxxed
2. This works with MySQL 4.0+
  #13 (permalink)  
Old 11-24-2004, 02:44 PM
Rael Rael is offline
myyyyy preeeeciooous
 
Join Date: Jan 1970
Posts: 18,055
Send a message via AIM to Rael Send a message via MSN to Rael
Default

Right. We'll have to keep searching for ways around that, then. I was hoping InvisionFree wouldn't have fixxxed it; I guess they've outsmarted us this once
__________________
<smallfont>\"I\'ll show you politics in America. Here it is, right here. \'I think the puppet on the right shares my beliefs.\' \'I think the puppet on the left is more to my liking.\' \'Hey, wait a minute, there\'s one guy holding out both puppets!\'\"
  #14 (permalink)  
Old 11-24-2004, 02:47 PM
Edmunds's Avatar
Edmunds Edmunds is offline
Administrator
 
Join Date: Mar 2004
Posts: 19,347
Default

Seeing how it says Invision Board has already released an official patch, I think most IB users have fixxxed it by now.
  #15 (permalink)  
Old 11-24-2004, 02:50 PM
Rael Rael is offline
myyyyy preeeeciooous
 
Join Date: Jan 1970
Posts: 18,055
Send a message via AIM to Rael Send a message via MSN to Rael
Default

Probably. What we really need to do is find an exploit no one knows about. I was hoping you'd look at the source and see if you could work something out, like that cookie replace you used on GE. imp:
__________________
<smallfont>\"I\'ll show you politics in America. Here it is, right here. \'I think the puppet on the right shares my beliefs.\' \'I think the puppet on the left is more to my liking.\' \'Hey, wait a minute, there\'s one guy holding out both puppets!\'\"
  #16 (permalink)  
Old 11-26-2004, 02:10 AM
Rael Rael is offline
myyyyy preeeeciooous
 
Join Date: Jan 1970
Posts: 18,055
Send a message via AIM to Rael Send a message via MSN to Rael
Default

Now that I've been thinking of it, a lot of OD members are here. What are the odds that they're using the same passwords on OD and here? Rather high, since they're not very bright. We only have their encrypted passwords, but that's probably enough to hack into their accounts and get a glance at their staff forums.

If no one's tried it by the time I get back on Saturday, I'll do it myself. imp:
__________________
<smallfont>\"I\'ll show you politics in America. Here it is, right here. \'I think the puppet on the right shares my beliefs.\' \'I think the puppet on the left is more to my liking.\' \'Hey, wait a minute, there\'s one guy holding out both puppets!\'\"
Closed Thread


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 05:18 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0
foot
The Hylia Copyright