Buy Official Merchandise!
Forumwarz is the first "Massively Single-Player" online RPG completely built around Internet culture.

You are currently looking at Flamebate, our community forums. Players can discuss the game here, strategize, and role play as their characters.

You need to be logged in to post and to see the uncensored versions of these forums.

Log in or Learn about Forumwarz

Civil Discussion
Switch to Role-Playing Civil Discussion
Bug - 3 Possible Vuln: Community Ad's

rush68

Avatar: 115996 Sun Jan 25 01:50:29 -0500 2009

Level 20 Hacker

Hard gay hooooooooo

So after posting some very special community ad’s (one of which I wanted deleted) I’ve come to realize a possible exploit.

Scenario is as follows.

1: I submit an ad cleverly worded, that links to something safe on my server

2: The ad gets approved by one of the mods

3: The ad goes public

4: I change the content on my server to redirect to either a fake log in page, a known exploit in common browsers, etc or worse set the content type of the file being linked (through php/etc) to an executable/download thus making it look like a file comes directly from the ad and trojan/etc **** up.

5: The acting mods go insane as they can’t change content in the ad’s. To quote ”... there is no feature in place to modify an existing ad. Yes, ...”

Besides that problem, the mods as far as I know should have the power to edit community ad’s already (dead links 404/403’s, content that gets changed etc) in case this sort of **** happens anyways.

Hackmeister

Avatar: Code (Blue)
4

Level 35 Hacker

“43 4f 44 45 20 4d 41 53 54 45 52”

Good thinking…but would’ve been way better to use the private bug report message to suggest your scenario to CZ.

pieyum

Avatar: 104284 Thu Jan 22 21:59:47 -0500 2009
7

[Vacation Hideaway]

Level 33 Hacker

“01001000 01000001 01011000”

If you had sent it as a bug report you could have gotten the haxplotation e-peen

quangntenemy

Avatar: 14557 2011-10-31 11:07:55 -0400
59

[WeChall]

Level 69 Troll

:ronpaul: :****ing sucks:

It could work but I suppose only new players would fall for that and you’ll get banned soon enough.

Still it would make sense to allow the mods to edit such thing.

TUBSWEETIE

Avatar: 3450 2011-07-31 00:45:06 -0400
28

[And The Banned Pla-
yed On
]

Level 37 Troll

MY MEMORY IS THAT OF A SMALL GRAPE

You would be banned and ET would pull down the ad.

Is this actually the first time somebody has thought of this and told people?

Inertia

Avatar: 60995 Fri Apr 03 12:59:05 -0400 2009
34

[Shii is gay]

Level 35 Troll

also wow i have no male reproductive organ

i am reminded of falconfour

rush68

Avatar: 115996 Sun Jan 25 01:50:29 -0500 2009

Level 20 Hacker

Hard gay hooooooooo

Hackmeister Posted:

Good thinking…but would’ve been way better to use the private bug report message to suggest your scenario to CZ.

“Start a thread in game discussion, AND submit a bug report. I’ll link the report to the thread and ET will then decide what, if anything, he wants to do about it.” -MCB

Too late, Hambanner suggested that I do the cross posting

MC Banhammer

Avatar: 1887 2011-07-31 00:40:59 -0400
36

[Good Omens]

Level 69 Troll

Trying to create drama to drum up the ratings by any means necessary!

rush68 Posted:

”Start a thread in game discussion, AND submit a bug report. I’ll link the report to the thread and ET will then decide what, if anything, he wants to do about it.” -MCB

Too late, Hambanner suggested that I do the cross posting

I suggested that because I thought you were going to report it as a problem (an ad which became irrelevant because it was advertising an expired auction or contest), not as an exploit. If I thought you’d be reporting it as an exploit I would’ve told you to do the bug report and keep it to yourself, for the peen.

rush68

Avatar: 115996 Sun Jan 25 01:50:29 -0500 2009

Level 20 Hacker

Hard gay hooooooooo

MC Banhammer Posted:

....for the peen.

Peen is irrelevant to me. Just wanted to get it out of the way in hopes it would speed up you mods having more power.

Internet Delay Chat
Have fun playing!
To chat with other players, you must Join Forumwarz or Log In now!