You are currently looking at Flamebate, our community forums. Players can discuss the game here, strategize, and role play as their characters.
You need to be logged in to post and to see the uncensored versions of these forums.
![]() |
|||||||
---|---|---|---|---|---|---|---|
|
When asking for the Haxploitation E-Peen you informed me that it wasn’t given out for bugs, but only for security issues. The bug in question was that when pressing the prank bumon on a user page 1 BP allowed you to change a user’s Avatar, normally 2 points, but an inability to change their title. I put forth the argument that if this were to go unnoticed that it would have threatened FW’s financial security by allowing players to effective steal one BP per Avatar prank from you. In practice, you would have had theft at $1.67 per avatar change by anyone who abused this, bumuming they bought the 3 BP package. Please, get back to me. |
||||||
Posted On: 12/05/2008 4:08PM | View Deific Blunder's Profile | # | ||||||
|
You’re supposed to tubmail him so the whole community doesn’t know about the bug before it’s fixed, iirc.
Also you’re wrong, it’s still 2-3BP for avatars, 1-2BP for titles Johnny Mac edited this message on 12/05/2008 4:12PM |
||||||
Posted On: 12/05/2008 4:11PM | View Johnny Mac's Profile | # | ||||||
|
Johnny Mac Posted:
he fixed it maybe?
edit: removed trollan, damn game discussion Master_Troll edited this message on 12/05/2008 4:13PM |
||||||
Posted On: 12/05/2008 4:13PM | View Master_Troll's Profile | # | ||||||
|
Master_Troll Posted:
Yeah, he already fixed it, then told me no. That’s why I’m putting forth my argument. |
||||||
Posted On: 12/05/2008 4:14PM | View Deific Blunder's Profile | # | ||||||
|
Deific Blunder Posted:
oic, well then I don’t really have an opinion on this. |
||||||
Posted On: 12/05/2008 4:16PM | View Johnny Mac's Profile | # | ||||||
|
Johnny Mac Posted:
S’all good. I can understand how it can be confused without providing proper background. |
||||||
Posted On: 12/05/2008 4:18PM | View Deific Blunder's Profile | # | ||||||
|
ah yes I also did.. |
||||||
Posted On: 12/05/2008 4:44PM | View Inertia's Profile | # | ||||||
|
I’m not trolling, but I think that is a valid security issue. |
||||||
Posted On: 12/05/2008 4:47PM | View Deific Blunder's Profile | # | ||||||
|
Good Luck, kid. Arktor and I both advised CZ about the infinite Scoops & Cards glitch, and we never got a response. It wasn’t until we finally decided to stage a protest and get about 5000+ scoops in each of our Dom Brackets that anything got fixed.
Major Haxploitation Reported, and never even got an acknowledgment. |
||||||
Posted On: 12/05/2008 5:19PM | View Acid Flux's Profile | # | ||||||
|
Acid Flux Posted:
I hear ya, but theft of real money from the website, I would contest, is indeed a major Haxploitation. |
||||||
Posted On: 12/05/2008 5:25PM | View Deific Blunder's Profile | # | ||||||
|
did myspace tom get haxploitation peen? edit: ah he did. ask for one when you’ve accomplished what he’s accomplished. Inertia edited this message on 12/05/2008 5:41PM |
||||||
Posted On: 12/05/2008 5:39PM | View Inertia's Profile | # | ||||||
|
Inertia Posted:
The E-Peen isn’t meant to be judged according to other peoples catches. I think I found a valid exploit, which I pointed out, then he fixed, that could have been used to avoid paying real money to FWz for product they sell to enhance their game. Is it a vast sum of money? No, but it is still money that would have been lost due to a flaw in coding, that people could have abused. I feel that is the very definition of what they award the E-Peen for to avoid. If ET comes on here and completely disagrees, well, there is nothing I can do about it. I would hope he would explain why, but I see this as an honest E-Peen request for something I caught. |
||||||
Posted On: 12/05/2008 6:01PM | View Deific Blunder's Profile | # | ||||||
|
Acid Flux Posted:
Tell me more about this 50000 scoops story
|
||||||
Posted On: 12/05/2008 7:56PM | View LROSENBERG1996's Profile | # | ||||||
|
Someone here is confused between bug vs exploit Log in to see images! |
||||||
Posted On: 12/05/2008 11:29PM | View quangntenemy's Profile | # | ||||||
|
quangntenemy Posted: |
||||||
Posted On: 12/06/2008 8:56AM | View Deific Blunder's Profile | # | ||||||
|
Bump in hopes of ET or Binge seeing this. |
||||||
Posted On: 12/06/2008 10:26AM | View Deific Blunder's Profile | # | ||||||
|
So is it a piece of software, a chunk of data, or sequence of commands? |
||||||
Posted On: 12/06/2008 10:36AM | View quangntenemy's Profile | # | ||||||
|
quangntenemy Posted:
Yes, by going to a player page to the prank bumon instead of through the “Support Us!” tab to purchase the avatar change, you are using a sequence of commands to cirgreat timesvent the normal price of the prank. bumons and tabs are shortcuts for commands, there was a flaw in the way it was setup, thus enabling an exploit. |
||||||
Posted On: 12/06/2008 10:54AM | View Deific Blunder's Profile | # | ||||||
|
OK and how do u define haxploitation? |
||||||
Posted On: 12/06/2008 11:26AM | View quangntenemy's Profile | # | ||||||
|
haxploitation is for important things |
||||||
Posted On: 12/06/2008 12:02PM | View Veer's Profile | # | ||||||