Quantcast

Jump to content


Photo

Not so fixed Search Threat


  • This topic is locked This topic is locked
32 replies to this topic

#1 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 05:40 PM

To protect codex, this post has been edited by cataliste. The admins know the fucking problem :p

Edited by Cataliste, 15 May 2006 - 06:54 PM.


#2 pyke

pyke
  • 13686 posts


Users Awards

Posted 15 May 2006 - 05:47 PM

I say cat's right. It'd probably be best to patch up as a forum rather then notify ipb and wait for a possible patch.

*posts his greivances!*

#3 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 05:50 PM

Please submit a bug report to IPB. They are the professionals and will be able to properly patch it :).

#4 juju

juju
  • <img src='http://i31.tinypic.com/iyg3ut.png'>

  • 5085 posts


Users Awards

Posted 15 May 2006 - 05:51 PM

:o We should fix this ASAP. If you didn't explain it I would've been lost xD, nice find.

#5 cara

cara
  • 56/m/mexico

  • 3364 posts


Users Awards

Posted 15 May 2006 - 05:52 PM

:o We should fix this ASAP.



#6 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 05:52 PM

Cataliste: please submit a bug report to IPB so that every board out there who uses this software can be patched :). Thanks. :).

#7 pyke

pyke
  • 13686 posts


Users Awards

Posted 15 May 2006 - 05:53 PM

Please submit a bug report to IPB. They are the professionals and will be able to properly patch it :).

That could take a while though couldn't it? By the sounds of it, at least a quick temporary fix could be made and a report could be sent in order to bring the patch to other forums eventually?

#8 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 05:53 PM

Hydrogens take on it:

No it wasn't as I can still do it.

Please submit a bug report to IPS then. http://www.invisionpower.com

I am jsut trying to help protect codex. jsut because IPB didnt patch does not mean we should not. Do not try to blow me off with the "CEO" business and tell me to submit a bug report. al you need to do is cleans the search_id and then force them through the search function again to make sure its a fresh id instead of an old one. The current function only checks when i new ID needs to be created, not if one is already supplied.

that sort of stuff is too advanced for me. lets help the entire community no? :)

SL knows how to fix it, yet he has been to lazy. it needs to be done, thats whats best for the community

lets give it to the professionals who write the software.

and leave codex wide open? you got lucky and missed the 2.1.5 exploit allowing access to your admin password by day! ONE DAY! this isn't patched. i found it myself. that means loads of people already have it!

Like i said :). Please submit a bug report to the professionals :). I dont claim to be a professional and im telling you now that i dont know how to fix it nor do i have the time to figure out how. Give it to the professionals and let them handle it :).



pretty much: "We will wait for IPB to fix it, in the meantime, lets get DoSed!"

Gay >_>

#9 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 05:57 PM

I really dont appreciate the fact that you release personal messages that i send to you without my permission. But hey, you hold yourself to different morals than i do.

Anyway, now that that personal message is released, you will all know that i do not know how to fix this error at this current time. Shadowlink, however, does. So we can wait for him to help us out :). Until then, lets let IPS know of this so that they can start working on a fix :).

#10 .:Orange:.

.:Orange:.
  • 1168 posts

Posted 15 May 2006 - 05:59 PM

Err...it might be a good idea to patch that. There are certain people that would love to DoS us. =/

#11 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:00 PM

I really dont appreciate the fact that you release personal messages that i send to you without my permission. But hey, you hold yourself to different morals than i do.

Anyway, now that that personal message is released, you will all know that i do not know how to fix this error at this current time. Shadowlink, however, does. So we can wait for him to help us out :). Until then, lets let IPS know of this so that they can start working on a fix :).

I hold myself to different morals than you? I think not. I was simply letting everyone know aobut you :don't give a shit" attitude. It morally irresponsible to let a weakness like this exist in the boards that your users enjoy everyday.

I also think it was morally wrong to try and make me look like an idiot in my prvious thread stating: "It was already fixed".

Thats lying to the members and trying to make me look like a fool.

Who has the great moral code here?

#12 Mr. Hobo

Mr. Hobo
  • 8152 posts


Users Awards

Posted 15 May 2006 - 06:03 PM

Cata, let Hydro do what he decides best. He may not have time to fix it now or may want to wait for IPB to fix it for different reasons. You bringing this to the public increased the risk tenfold. I'm sure everyone appreciates your willingness to help protect Codex and that you've found a security breach and gave a fix but now its up to the admins to decide what to do.

#13 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 06:05 PM

I hold myself to different morals than you? I think not. I was simply letting everyone know aobut you :don't give a shit" attitude. It morally irresponsible to let a weakness like this exist in the boards that your users enjoy everyday.

I also think it was morally wrong to try and make me look like an idiot in my prvious thread stating: "It was already fixed".

Thats lying to the members and trying to make me look like a fool.

Who has the great moral code here?

Please dont assume what my intentions were. They were not to make you look bad. I'm not interested in doing that to anyone. And if you still feel this way, then I apologize to you in the most humblest of ways. I really hope that you can forgive me.

I hope you can also understand my position. I never claim that I know how this software works 100% of the time and with that, there will undoubtedly be times where i simply dont know. This is one of those times. So im trying to do the next best thing for the board and that is to wait for SL who you say knows how to fix it. And at the same time, let IPS know so they can work on an official fix so that all the forums who use invision power board can also patch their software :).

Once again, I'd like to emphasize that my intentions were not to lie to anyone or to make you look unknowledgable. I suppose I was just mistaken and I wholeheartedly hope that you will forgive me if i have transgressed upon you in any way.

I'd also like to ask any member who feels that I am not able to provide for this board as much as they would wish to forgive me and understand that I am also human and a student just like many of us. I have outside responsibilities as well and issues going on in my own life which also need to be taken care of. If at any time, I am not able to fulfill the responsibilities that I have taken up as an administrator of Neocodex, then please forgive me and pray that one day those responsibilities will be fulfilled, whether it is through me or through someone more capable :).

#14 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:05 PM

Cata, let Hydro do what he decides best. He may not have time to fix it now or may want to wait for IPB to fix it for different reasons. You bringing this to the public increased the risk tenfold. I'm sure everyone appreciates your willingness to help protect Codex and that you've found a security breach and gave a fix but now its up to the admins to decide what to do.

Just pissis me off he tried to play it off as being fixe din the first thread. And now he questions my morals. I brought it to public because it NEEDS to be fixed ASAP.

#15 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 06:09 PM

Just pissis me off he tried to play it off as being fixe din the first thread. And now he questions my morals. I brought it to public because it NEEDS to be fixed ASAP.

I apologize that it seemed that way and hope that you forgive me for my misjudgement. I was misinformed and truly thought that it had been fixed in the last security update.

Please read my above post for what i think we should do :).

#16 pyke

pyke
  • 13686 posts


Users Awards

Posted 15 May 2006 - 06:10 PM

Calm down cat, I am pretty sure that wasn't hdros intentions.

#17 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:17 PM

I jsut sent Hydrogen a modified PERL script that would do the trick in DoSing us. Maybe it will get this fixed faster, since a month was not enough time.

#18 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 06:18 PM

I jsut sent Hydrogen a modified PERL script that would do the trick in DoSing us. Maybe it will get this fixed faster, since a month was not enough time.

Thanks :). Im going to show it to SL as you said he knows how to fix it :). Please read my other posts too Cataliste :). They are important as well :). Just scroll up :).

#19 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:20 PM

I read them the first time Hydro. they just seemed a little condecending. Maybe lay off the smiley faces?

#20 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 06:22 PM

I read them the first time Hydro. they just seemed a little condecending. Maybe lay off the smiley faces?

Ah. I was only trying to humbly ask for your forgiveness. If you dont like smiley faces.Then no more smiley faces. For the record though, i only used 3 in about 700 words...

I didnt mean to be condescending nor did i think i was being condescending. If you got that impression, then I hope you can forgive me for that too.

I'm really not sure what I did to make you so angry with me. I'm only trying to do what is best for the board and at the best of my ability. But I am more than willing to do what is necessary to have you forgive me for any transgression that i made upon you.

Just let me know.

#21 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:28 PM

Maybe talk to me on MSN or Gmail? We were best buds, you never speak to me now...

#22 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 06:30 PM

Maybe talk to me on MSN or Gmail? We were best buds, you never speak to me now...

I dont see why we arent still best buds :). I dont really talk to anyone now as I dont even have time for myself. I guess a lot has changed since you left. I entered college as a computer science and engineering major. I suppose i dont say these things to many people but i come home at around 2:30 am every morning because of programming and then get up at 5:30 am for prayer and do homework until my first class begins.

The very reason i am sick right now is because i am missing meals and am exhausted with all the work involved at college. Classes along with MSA and other stuff that i have to do coupled with a family tragedy in progress as we speak...im still not sure how i am sane at this moment.

I guess all i can ask is that you bare with me :). I ask that of anyone who reads this :). Just bare with me :).

#23 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:34 PM

You find time for codex! you can't find even a little for me?

#24 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 15 May 2006 - 06:36 PM

You find time for codex! you can't find even a little for me?

Alright :). I will do my best :). I promise.

And just an update...were working on this bug :). And we are going to submit it to IPB for an official patch as well :).

#25 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 15 May 2006 - 06:39 PM

Yay, codex gets fixed, and I get my friend back ^_^


i want my name on the portal, plus a link to a shrin of me. jsut so people know i fixe dit.

PS "[email protected]" on google chat and MSN. my aim and shit i aint eve ron


1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users