Update 14.2

Discussion in 'BBase' started by Teddi, Aug 25, 2010.

Thread Status:
Not open for further replies.
  1. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    • Fixed an exploit where users could use one forum account to gain plat bonuses across multiple steam accounts.
     
  2. Bundt

    Bundt DJ Pauly D MVP

    Joined:
    Jul 28, 2009
    Messages:
    1,262
    Likes Received:
    36
    Hope you banned that person who used it.
     
  3. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    Well, he came clean about it, and there's no trace if other people used it. But it's in place so it can't happen again.
     
  4. Mc Diddles

    Mc Diddles <marquee><font size="3" color="blue">Justice Team<

    Joined:
    Sep 9, 2009
    Messages:
    1,642
    Likes Received:
    3
    I raged at him. Same with Halo and Roflpancake.

    Christ I'm pissed.
     
  5. Bundt

    Bundt DJ Pauly D MVP

    Joined:
    Jul 28, 2009
    Messages:
    1,262
    Likes Received:
    36
    who was it?
     
  6. Whitefang

    Whitefang ( ͡° ͜ʖ ͡°)

    Joined:
    Jul 12, 2008
    Messages:
    4,009
    Likes Received:
    43
    Seriously Teddi we've talked about this.
     
  7. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    No we hadn't.
     
  8. Whitefang

    Whitefang ( ͡° ͜ʖ ͡°)

    Joined:
    Jul 12, 2008
    Messages:
    4,009
    Likes Received:
    43
    Yes we have.
     
  9. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    If we had, I would have tested it and fixed it sooner. No, we haven't.

    Your herpes on the other hand, we have.
     
  10. Whitefang

    Whitefang ( ͡° ͜ʖ ͡°)

    Joined:
    Jul 12, 2008
    Messages:
    4,009
    Likes Received:
    43
    I was talking about security in general. Also I thought it was Elk's herpes you gave her?
     
  11. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    We discussed something else a while back, but it wouldn't work either way and you couldn't get it to work either.

    Nope, I'm clean.
     
  12. Bundt

    Bundt DJ Pauly D MVP

    Joined:
    Jul 28, 2009
    Messages:
    1,262
    Likes Received:
    36
    Free Herpes testing in my office that way ----------------------------->
     
  13. Whitefang

    Whitefang ( ͡° ͜ʖ ͡°)

    Joined:
    Jul 12, 2008
    Messages:
    4,009
    Likes Received:
    43
    I still don't get why not, but I've told you to clean up your code so many times :(
     
  14. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    Just to explain what the exploit did -

    • User paid for Platinum
    • User then linked account
    • User's friend then linked to same account
    • Both users would gain platinum for that map
    • Person who originally paid would lose platinum, would have to relink
    • Person's friend would still have it until the next map
    • And so on.

    The problem was is that the script (ask Ben or Cpf, they're the ones who originally wrote this, I just ported it) it only checked to see if the SteamID was ever in use. It never checked if the forum account actually had the field. This enabled this exploit which has now been closed. It wasn't a question of dirty code (and my code isn't dirty :( ) or bad scripting, it was just a check was never put in place to ensure this couldn't be done.

    This check is now in place and people can't do this. By the way, this exploit has existed for well over three years, and possibly dates back to the old PHPBB3 forums.

    And the reason your exploit doesn't work Whitefang is because I check to see if the ent even exists in a table before we go any further.
     
  15. Whitefang

    Whitefang ( ͡° ͜ʖ ͡°)

    Joined:
    Jul 12, 2008
    Messages:
    4,009
    Likes Received:
    43
    Your code is dirty because you have a nag to put BBRP.*** infront of every fucking function when it doesn't need to be global.
     
  16. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    Tabled function. So what, and if you're going to localize something which is used often, you're going to give the garbage collector a heart attack, thus causing more crashes than really wanted. Localisation of functions is only ideal if it's not used that often.
     
  17. Mc Diddles

    Mc Diddles <marquee><font size="3" color="blue">Justice Team<

    Joined:
    Sep 9, 2009
    Messages:
    1,642
    Likes Received:
    3
    I just thought. I've done this before when I switched steam accounts.

    I never play deathrun on the other account, and I asked teddi to help me out. Surely you must of noticed it then.
     
  18. Teddi

    Teddi Well-Known Member Bear

    Joined:
    Jul 21, 2007
    Messages:
    9,635
    Likes Received:
    1,118
    I didn't twig at the time.
     
  19. Overlord

    Overlord lolz to can't say @dmin

    Joined:
    Jun 7, 2008
    Messages:
    1,136
    Likes Received:
    4
    Whitefang ment "Security" in general of "Everything". One man with lots of Bots won´t fix everything.

    Also with the forum´s exploits of being slow due to porn spamms from the interwebz of teddi bears.
     
  20. Mc Diddles

    Mc Diddles <marquee><font size="3" color="blue">Justice Team<

    Joined:
    Sep 9, 2009
    Messages:
    1,642
    Likes Received:
    3
    Porn spamming is fine.

    At least in my rules.
     
Thread Status:
Not open for further replies.