it happened to me when i reported the photo on another topic... It´s getting out of the admin hands....
0 Replies
momoends
1
Reply
Fri 14 Oct, 2016 10:40 pm
@edgarblythe,
he´s all over the place
0 Replies
Robert Gentel
5
Reply
Sat 15 Oct, 2016 12:58 am
@edgarblythe,
This bug should be fixed. There was a bug in the bbcode parser library the site uses that allowed arbitrary html injection into the color tag. The "hacker" kids who did this used that bug to post a javascript that would post the message over and over if you viewed one of the posts. The posts have been removed and the bbcode parser's bug has been fixed.
They (?) must have used keystroke logging to make the false posts, because i was there, but i wasn't logged in; i looked at the threads, but i don't believe they logged in on my account and propagated their awful thread.
You can delete your own thread for approximately ten minutes, and then you can't, unless I'm remembering wrong, which I suppose is possible.
0 Replies
Robert Gentel
5
Reply
Sat 15 Oct, 2016 10:48 am
@Setanta,
As far as I know no user computers or servers were compromised (so no keystroke loggers etc). There was a bug in the bbcode library we use that let a carefully crafted post insert html. Doing that allowed them to link to a javascript, the javascript made the browser try to post the threads and if you were already logged in it worked. We patched the bug in the bbcode library that allowed the html so that won't work again.
I was not certain. Did a whole computer scan just in case.
0 Replies
Setanta
2
Reply
Sat 15 Oct, 2016 12:04 pm
I'm glad to think that "they" weren't getting anyone's passwords or credit card numbers. While i'm here, thanks to you and Peter.
0 Replies
Krumple
0
Reply
Sat 15 Oct, 2016 12:42 pm
@Robert Gentel,
Robert Gentel wrote:
As far as I know no user computers or servers were compromised (so no keystroke loggers etc). There was a bug in the bbcode library we use that let a carefully crafted post insert html. Doing that allowed them to link to a javascript, the javascript made the browser try to post the threads and if you were already logged in it worked. We patched the bug in the bbcode library that allowed the html so that won't work again.
What do we do about the trauma from seeing that post?