Mysidia Adoptables Support Forum  

Home Community Mys-Script Creative Off-Topic
Go Back   Mysidia Adoptables Support Forum > Mysidia Adoptables > Questions and Supports

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-07-2017, 12:08 AM
KatFennec's Avatar
KatFennec KatFennec is offline
Member
 
Join Date: Apr 2017
Posts: 57
Gender: Female
Credits: 7,853
KatFennec is on a distinguished road
Angry User made visiting their profile an autoban

Title says most of it. You can put a pound confirmation into the avatar URL slot, which makes viewing their profile an autoban. This could be a very serious problem, as you can also go and trick a user into approving the pounding of one of their pets, or any number of other such things. Any suggestions on fixing this, and also possibly removing the auto-bans?
__________________
Reply With Quote
  #2  
Old 06-07-2017, 12:37 AM
aquapyrofan aquapyrofan is offline
Member
 
Join Date: Apr 2017
Posts: 48
Gender: Unknown/Other
Credits: 8,439
aquapyrofan is on a distinguished road
Default

Quote:
Originally Posted by KatFennec View Post
Title says most of it. You can put a pound confirmation into the avatar URL slot, which makes viewing their profile an autoban. This could be a very serious problem, as you can also go and trick a user into approving the pounding of one of their pets, or any number of other such things. Any suggestions on fixing this, and also possibly removing the auto-bans?
This isn't just limited to avatars, theoretically someone could create an autoban on another site by linking to the page. This is clearly a major problem caused by the autoban system.
Reply With Quote
  #3  
Old 06-07-2017, 06:06 AM
Dinocanid's Avatar
Dinocanid Dinocanid is offline
Member
 
Join Date: Aug 2016
Location: Maryland, USA
Posts: 516
Gender: Unknown/Other
Credits: 65,305
Dinocanid is on a distinguished road
Default

I personally removed the autobans altogether, since it leads to unnecessary bans (IE: if a user happens to refresh on the pound for whatever reason, boom, banned. Same for adopt center) Here are a few links:
http://www.mysidiaadoptables.com/for...ead.php?t=4729 (removal)
http://mysidiaadoptables.com/forum/s...ead.php?t=5168 (redirect replace)

They can safely be replaced with redirects and other messages to serve the same function of preventing this (and possible inspect element hacking) without throwing autobans like confetti. Hope these are useful!
__________________
Reply With Quote
  #4  
Old 06-07-2017, 01:12 PM
aquapyrofan aquapyrofan is offline
Member
 
Join Date: Apr 2017
Posts: 48
Gender: Unknown/Other
Credits: 8,439
aquapyrofan is on a distinguished road
Default

I'm pretty sure that hypothetically speaking, while I couldn't pound someone else's pet, I could trick them into pounding their own. All I need is a PM (haven't checked images in PMs though) or shout (definitely would work there) and a little knowledge of how Mysidia and is set up.
Step 1. Get a pet I don't care about, to pound for the URL
Step 2. Set an image URL to the URL for confirming pounding + a little Mysidia Knowledge get their active pet's ID at the end
Step 3. Post in the Shoutbox, so anyone who visits has their active pounded.

Targeted version:
Step 1. Same
Step 2. Check around for the target pet, use their ID at the end of the URL.
Step 3. Set the URL to an image, either in the shoutbox, your avatar, or, if possible, a PM.
STEP 4. As the user would have to load it to even think about reporting it, they're not safe in PM, they'll get the target pet pounded. If it's an avatar or the shoutbox, everyone else who visits any page it appears on will get banned.

Or heck, do it on another site.

Not to mention the security holes caused by CKeditor happily allowing JavaScript.

Currently we're blocking the exploit on our site by disallowing anything as an avatar that isn't an image and has "pound" in the URL (because if it was just the former there's another exploit I found) using regular expressions, but there's got to be a better way.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 09:50 AM.

Currently Active Users: 9685 (0 members and 9685 guests)
Threads: 4,080, Posts: 32,024, Members: 2,016
Welcome to our newest members, jolob.
BETA





What's New?

What's Hot?

What's Popular?


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
vBCommerce I v2.0.0 Gold ©2010, PixelFX Studios
vBCredits I v2.0.0 Gold ©2010, PixelFX Studios
Emoticons by darkmoon3636