Congrats while it lasted, quite ingenious honestly. We will be implementing a simple patch, hopefully tomorrow morning. (Credit to Pyroka)
Congrats while it lasted, quite ingenious honestly. We will be implementing a simple patch, hopefully tomorrow morning. (Credit to Pyroka)
It costs nothing to be a good friend.
American and Proud
I also use the account nvrspk on other computers.
![]()
Yes, very ingenious. I wonder who started it off.
I'm pretty sure things like these are impossible to patch without adding a security token to each form.
Look up CSRF/XSRF.
I would show you the simple patch however I feel like someone would find a workaround so we'll let them discover it without our help.
It costs nothing to be a good friend.
American and Proud
I also use the account nvrspk on other computers.
![]()
Im sure people will find a way arround it anyway
You could simply change the change style form at the bottom of the page to use $_POST then it cannot be changed unless someone submits it.
Last edited by Decode; 15-08-2008 at 08:53 AM.
Lets set the stage on fire, and hollywood will be jealous.
EDIT: It's also possible to do this with Habbox's radio request system (I won't say how). I'm sure 300 of the same request from different people would piss off the DJs, although it might convince them to play some death metal.
EDIT: I pressed quote instead of edit by accident.
EDIT: I was past the edit limit anyway.
Last edited by Jxhn; 15-08-2008 at 10:34 AM.
I didnt mean the '-.-' at you, it was directed at the noobs who are doing it.
Yup. Me and Mecto were testingo n our forum and you can do that. its also is/was(?) possible to log users out and redirect them.EDIT: It's also possible to do this with Habbox's radio request system (I won't say how). I'm sure 300 of the same request from different people would piss off the DJs, although it might convince them to play some death metal.
EDIT: I pressed quote instead of edit by accident.
EDIT: I was past the edit limit anyway.
Glad to see that is has/is being patched![]()
The other day I was in a toilet.
A voice came from the cubicle next to me: "Hello mate, how are you doing?"
I didn't want to be rude, so I said, "Not too bad, thanks."
I heard the voice again. "So, what are you up to?"
Again I answered, "Just having a quick ****... How about yourself?"
Then I heard him say "Sorry, mate, I'll have to call you back. I've got some **** in the cubicle next to me answering everything I say."
Can't you just filter the styleid= or something?
That's why we seize the moment, try to freeze it and own it, squeeze it and hold it cause we consider these minutes golden.
That's just filtering out one problem, there's many things they could do with the [IMG] tag. It's not limited to just changing styles on a forum so they needed something more generic. Either way, it's done now.
Last edited by Decode; 15-08-2008 at 11:08 AM.
Lets set the stage on fire, and hollywood will be jealous.
Want to hide these adverts? Register an account for free!