You are not enjoying the benefits offered by registering. To register click here...
  
Forums | Prefs | Your Messages | Members | Recent | Search
Quick Search


Advanced Search
| Calendar | Doc | Dev' Blog! |
Chat (Alpha Version)

Guest, do not forget to login ( Register )
 Top > Forums > This Software > I want to help!
 Some little problems

Skin Selection:
 (1 pages) 1  
Burning Ice

Local Hero
Group: Testers
Posts: 72
Reputation: 5


Posted on Jan 29, 2008, 9:08 am by Burning Ice
Some little problems

Hello,

I've tried a few browsers and most of the functions of the forum.
Opera web browser doesn't seems to be compatible with the software...?
The menu with the   B  I  U   ABC   etc in it, isn't showing up (code buttons yes, but those below not).
Also when submitting a post, the software seems to freeze...

Another little problem i've noticed, is with the skins...
Iff an user selects a skin with "Skin Selection", and the admin deletes the skin later, the user isn't able to get back on the forum with his account...

Greetz


You can do it if you really want it... - - - see my testforum (0.5.3)
 
Top

Burning Ice

Local Hero
Group: Testers
Posts: 72
Reputation: 5


Posted on Jan 29, 2008, 9:14 am by Burning Ice

A  screenshot of opera with the missing bar and where it freezes:
(sorry for its size...)


You can do it if you really want it... - - - see my testforum (0.5.3)
 
Top

Burning Ice

Local Hero
Group: Testers
Posts: 72
Reputation: 5


Posted on Jan 29, 2008, 11:27 am by Burning Ice
Security...

My cousin is kind of a geek, shows me this: 

http://www.geilepraat.be/?do=handlemsg&act=msg&MessageRecipient="><marquee>This%20page%20could%20be%20hacked</marquee>

http://www.geilepraat.be/?do=main&action=notifier&level=2&first=0 

The first example is just messing with the browser, nothing special...
The second example is pretty risky, not?  

My cousin tells me that someone who's good in SQL could inject whatever he wants in the database. 

None of these actions gives a notification in the log...
I guess you guys knew this already but I  mention it anyway... 

Greetz



Last edit by Burning Ice on Jan 29, 2008, 11:29 am
You can do it if you really want it... - - - see my testforum (0.5.3)
 
Top

Burning Ice

Local Hero
Group: Testers
Posts: 72
Reputation: 5


Posted on Jan 29, 2008, 11:58 am by Burning Ice

When I turn of the board, I get the message that i've written in "modules on-off"
Ok.... but in the chatbox, I see alsoo the forum with the message...?




 


So iff I write something in the chatbox inside the chatbox... I get another forum in the second chatbox, so now have three chatboxes... lolz
 



You can do it if you really want it... - - - see my testforum (0.5.3)
 
Top

Burning Ice

Local Hero
Group: Testers
Posts: 72
Reputation: 5


Posted on Jan 29, 2008, 12:37 pm by Burning Ice
All admins are Chris F R? :)

When monitoring the memberlist, and pointing the cursor over the admins name, the name Chris F R appears...
How do we change that..?


You can do it if you really want it... - - - see my testforum (0.5.3)
 
Top

Burning Ice

Local Hero
Group: Testers
Posts: 72
Reputation: 5


Posted on Jan 29, 2008, 12:40 pm by Burning Ice

In internet explorer 7 i'm missing a scroll bar in the acp...
Alsoo i have some problems when i click on the topics... still, on this forum i don't have this problem so probably a settings error of me...
 


You can do it if you really want it... - - - see my testforum (0.5.3)
 
Top

chris

The Culprit
Group: Admins
Posts: 1,541
Reputation: 38


Posted on Feb 1, 2008, 3:26 am by chris

 Burning Ice wrote:
My cousin is kind of a geek, shows me this: 

http://www.geilepraat.be/?do=handlemsg&act=msg&MessageRecipient="><marquee>This%20page%20could%20be%20hacked</marquee>

http://www.geilepraat.be/?do=main&action=notifier&level=2&first=0 

The first example is just messing with the browser, nothing special...
The second example is pretty risky, not?  

My cousin tells me that someone who's good in SQL could inject whatever he wants in the database. 

Thanks for the report. Your cousin is right that it is important to keep an eye out for xss and sql injections. We are always interested in finding potential vulnerabilities, which is a lot of work on a program the size of nBBS.

Now, regarding both examples:

  1. This could be construed as an example of xss injection. However since you're only displaying the marquee to yourself, it does not qualify.
  2. This one looks scary because there's an SQL error. It looks a bit messy, due to the fact that level 2 does not contain messages and we end up using -1 as offset. We can add a test and make sure that it's always 0 or positive.
    This is not the same as an arbitrary SQL injection, however: nothing is injected here, you are simply using an existing feature.

Cheers,

-C.



 
Top

chris

The Culprit
Group: Admins
Posts: 1,541
Reputation: 38


Posted on Feb 1, 2008, 3:30 am by chris

 Burning Ice wrote:
When I turn of the board, I get the message that i've written in "modules on-off"
Ok.... but in the chatbox, I see alsoo the forum with the message...?




 

So iff I write something in the chatbox inside the chatbox... I get another forum in the second chatbox, so now have three chatboxes... lolz
 

Ha! That, my friend, is what we call "a bug"



 
Top

tuxg33k


Newbie
Group: Members
Posts: 4
Reputation: 0


Posted on Feb 6, 2008, 2:15 am by tuxg33k

 chris wrote:
 Burning Ice wrote:
When I turn of the board, I get the message that i've written in "modules on-off"
Ok.... but in the chatbox, I see alsoo the forum with the message...?




 

So iff I write something in the chatbox inside the chatbox... I get another forum in the second chatbox, so now have three chatboxes... lolz
 


Ha! That, my friend, is what we call "a bug"

 

Any idea what causes this? I am having the same issue with the latest from sourceforge 0.50 runing on CentOS 5.

Thanks


 
Top

chris

The Culprit
Group: Admins
Posts: 1,541
Reputation: 38


Posted on Feb 12, 2008, 2:52 am by chris
Not at this point, no. You may have to disable chat by removing the chat tag for now.

 
Top

 (1 pages) 1 - Flat Mode | Threaded Mode  
Quick Jump:

         
Page generated in 0.04 seconds (Queries: 0.01) - Cpu: 0.06
Total DB [adodb:mysql] queries: 14
Total Strings Translated: 13
Powered by NextBBS SE v0.4.5 - Copyright © 2007 CFR & The NextBBS Team
Chatbox powered by smiletag