Page 1 of 3 123 LastLast
Results 1 to 10 of 22

Thread: Bypass 275 limit on AO Addicts forum.

  1. #1
    Senior Member
    Join Date
    Aug 2001
    Posts
    356

    Bypass 275 limit on AO Addicts forum.

    I believe I found a way to post to the AOAddicts forum with out having the required 275 posts. Unfortunately I can't confirm this because I cannot view the AOAddicts forum. However, my name is listed as the last poster to a few AOAddict threads. If someone can confirm that my posts were added to the restricted thread, I will be glad to share how to fix this bug with JP.

    --------------------------

    Note: Bug has now been fixed. Here is an explanation of how I was able to post in the AO Addicts area:

    Terr was on the right track when he mentioned manipulating the form input. What I did was I copied the HTML form for the Quick Reply, and saved it into an HTML file on my computer. Had to make some small modifications to the form such as removing the onsubmit command in the form tag, and making the action value point to the whole URL instead of just the php file. The thread ID you are replying to is coded in a hidden input type named "threadid". I changed the thread ID to the AO Addicts thread ID I wanted to post to. Then I just typed in what message I wanted, and clicked submit. It would post the message to the restricted forum. I still couldn't view the message because there was a post check before you can view AO Addicts messages, but I could still see my user name listed as the last person to post to that thread.

    Reasons why this would work would be that there was no post number check when submitting a reply to an AO Addicts forum, or there is no refer check to make sure the HTML form was being submitted from AO. I think in this case JP had the code there, but it wasn't working right for some reason. I'll leave that for him to go into details with, because I really don't know for sure what the code was on his end.

    But for the guys who do web development, take note that you should always have a refer check on your forms to make sure they are only being submitted from your site. Otherwise someone may simply be able to copy the HTML code, save it locally, and edit the hidden input types to their hearts content.

    Thanks to RCGreen for confirming that my posts did get added to the AO Addicts Forum. It was nice to see JP get right on this within minutes of me reporting the bug. Unlike some other companies that would wait weeks to fix it. ::: cough ::: microsoft ::: cough :::

    So JP, how about you give me access to the AO Addicts forum since I found and reported this bug? Hey, I had to ask.
    An Ounce of Prevention is Worth a Pound of Cure...
     

  2. #2
    AO Curmudgeon rcgreen's Avatar
    Join Date
    Nov 2001
    Posts
    2,716
    Now that's what I call hacking.
    I came in to the world with nothing. I still have most of it.

  3. #3
    AO Curmudgeon rcgreen's Avatar
    Join Date
    Nov 2001
    Posts
    2,716
    Yes, I'm an AOaddict and your posts are there.
    That's cool.
    I came in to the world with nothing. I still have most of it.

  4. #4
    Senior Member
    Join Date
    Aug 2001
    Posts
    356
    nice... thanks.
    An Ounce of Prevention is Worth a Pound of Cure...
     

  5. #5
    Senior Member
    Join Date
    Feb 2002
    Posts
    120
    So, how did you do it?
    Are you going to tell?
    \"To follow the path:
    look to the master,
    follow the master,
    walk with the master,
    see through the master,
    become the master.\"
    -Unknown

  6. #6
    Banned
    Join Date
    Jul 2001
    Posts
    1,100
    Greetings All:

    Well, I think that I have this fixed. Seems as though some dumb ass forgot to include a file in newthread.php and newreply.php.

    jared_c, if you were doing what it looks like you were, can you confirm that I now have the problem fixed?

  7. #7
    Senior Member
    Join Date
    Aug 2001
    Posts
    356
    I'm only going to tell JP until the bug is fixed. Reason why is because it seems like some more serious things on the site may be vulnerable to the tactic I used. Deleting PM's and entire Forums may be possible. I am not sure because I didn't want to go try that, but I'm going to keep it confidential until the bug is fixed just in case. After that though, I'll gladly share how it was done.
    An Ounce of Prevention is Worth a Pound of Cure...
     

  8. #8
    Senior Member
    Join Date
    Aug 2001
    Posts
    356
    It seems like it isn't fixed yet JP... I just posted to the Remark thread in the AO Addicts section. Would you like me to PM you exactly how I am doing this? It is an easy fix....
    An Ounce of Prevention is Worth a Pound of Cure...
     

  9. #9
    Fastest Thing Alive s0nIc's Avatar
    Join Date
    Sep 2001
    Location
    Sydney
    Posts
    1,584
    haha wow.. i like ur avatar jared.. lolz

  10. #10
    Senior Member
    Join Date
    Aug 2001
    Posts
    356
    Thanks s0nic... I'm working with JP right now to fix the bug.
    An Ounce of Prevention is Worth a Pound of Cure...
     

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •