|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| News of the Temple News about what's happening on this web site and BBS. Please keep posts on topic. |
 |
|
|
#1
 2007-07-05, 09:41
|
|
|
Whats this?
I was contemplating infracting one of the "ebaums" spammers, and came across this:
http://i6.photobucket.com/albums/y243/ArgonPlasma2000/huh.jpg?t=1183646393
PS: I refreshed again and it seems he is already tempbanned. Still, is the stalker ability accurate?
|
|
#2
 2007-07-05, 09:45
|
|
|
Re: Whats this?
Quite strange...Anyone with a bit of technical reasoning behind this?
|
|
#3
 2007-07-05, 11:16
|
|
Regular
|
|
Canberra Australia
|
|
Re: Whats this?
It's the name of the thread the person was making right? And not that they are in here. Someone that saw the leaked image perhaps? Maybe just a coincidence?
|
|
#4
 2007-07-05, 11:51
|
Mr.Happy 
Regular
|
|
|
|
Re: Whats this?
It can't show the name of the thread they're creating because they've not created it yet. As of then the thread name is just an entry in an unsubmitted form. I've seen it before and it shows the name of the forum they're creating a thread in.
Maybe one of us is the spammer?
*glares at everybody*
|
|
#5
 2007-07-05, 12:24
|
|
|
Re: Whats this?
Maybe one of us is the spammer?
*glares at everybody*
I blame the Jews
But an account needs to be under one of the special usergroups in order to see/access this forum...
|
|
#6
 2007-07-05, 12:32
|
|
Moderator
|
|
The Cahulawassee River
|
|
Re: Whats this?
I sense a disturbance in the Force.
|
|
#7
 2007-07-05, 13:56
|
|
|
Re: Whats this?
Quote:
|
Originally Posted by Social Junker
I sense a disturbance in the Force.
|
Sorry, I farted.
|
|
#8
 2007-07-05, 14:32
|
Entheogenic 
Regular
|
|
|
|
Re: Whats this?
This is just a hypothesis, but perhaps if one were to craft the URL that would start a new thread in this forum and send it, the status indicator would give that as the last activity even if the person didn't successfully authenticate. Someone with a non-privileged account can test this easily...
Entheogenic
|
|
#9
 2007-07-05, 14:49
|
|
|
Re: Whats this?
Possible, but what are the odds that you'll visit the profile of a spammer as they try that?
|
|
#10
 2007-07-05, 16:11
|
Mr.Happy 
Regular
|
|
|
|
Re: Whats this?
Quote:
|
Originally Posted by rabbhimself
Possible, but what are the odds that you'll visit the profile of a spammer as they try that?
|
If it happens once in a million, the single time it happened will seem like a minor miracle.
|
|
#11
 2007-07-05, 16:38
|
jebuonag 
Regular
|
|
|
|
Re: Whats this?
vBulletin has had a number of XSS vulnerabilities even in the 3.x.x releases that could be used to hijack a login session and escalate privileges when implemented properly. This may turn out to be nothing and current versions are relatively stable with regard to exploit impact and scope, but keep in mind the possibility.
|
|
#12
 2007-07-05, 16:57
|
|
|
Re: Whats this?
Creepy.
I allways wondered, if a regular user looks up latest posts by a moderator, will the results also show posts made in the Mods and Admins forum?
|
|
#13
 2007-07-05, 18:53
|
|
|
Re: Whats this?
Before, when I was stalking some of you people, if you clicked on the user profile it would often show:
Viewing Thread: ________
And that's it. So I don't think it shows the title, yet it's obvious where they're actually viewing it at.
|
|
#14
 2007-07-05, 18:54
|
MomentaryLapseOfReason 
Regular
|
|
|
|
Re: Whats this?
Before, when I was stalking some of you people...
I'm flattered. :)
|
|
#15
 2007-07-05, 19:00
|
|
Moderator
|
|
The Cahulawassee River
|
|
Re: Whats this?
Quote:
|
Originally Posted by yoyobek
Creepy.
I allways wondered, if a regular user looks up latest posts by a moderator, will the results also show posts made in the Mods and Admins forum?
|
Interesting question. Even if they couldn't access the content of a thread, the title alone could still give out a lot of information.
|
|
#16
 2007-07-05, 19:30
|
|
|
Re: Whats this?
Interesting question. Even if they couldn't access the content of a thread, the title alone could still give out a lot of information.
We can always post in Navajo. :o
|
|
#17
 2007-07-05, 19:32
|
|
Regular
|
|
Winston-Salem/Greensboro, NC
|
|
Re: Whats this?
We can always post in Navajo. :o
"Yo I studied you in school, you're a hunter-gather."
"I suppose you could call us that. I prefer the term....alcoholic"
/Dave Chappelle
|
|
#18
 2007-07-06, 12:25
|
|
|
Re: Whats this?
We can always post in Navajo. :o
Me, Angry. You, Argon.
Navajo - We no speak.

|
|
#19
 2007-07-07, 10:16
|
|
Forum Administrator
|
|
Columbus Ohio
|
|
Re: Whats this?
Quote:
|
Originally Posted by jebuonag
vBulletin has had a number of XSS vulnerabilities even in the 3.x.x releases that could be used to hijack a login session and escalate privileges when implemented properly. This may turn out to be nothing and current versions are relatively stable with regard to exploit impact and scope, but keep in mind the possibility.
|
At least the passwords are no longer stored in plain text in a cookie... They're encrypted in md5 (I think) so as long as your password is secure (returns 0 results on google) you should be pretty safe. Of course, like you said, it doesn't stop someone who's hijacking sessions.
PS: I left something for you on IRC.
|
|
#20
 2007-07-08, 20:34
|
|
Moderator
|
|
The Cahulawassee River
|
|
Re: Whats this?
We can always post in Navajo. :o
I'd prefer Esperanto. I just like saying that word, es-per-rant-tooo!
|
|
#21
 2007-07-08, 20:43
|
|
Regular
|
|
Winston-Salem/Greensboro, NC
|
|
Re: Whats this?
I'd prefer Esperanto. I just like saying that word, es-per-rant-tooo!
The song is pretty nifty as well.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|