Go Back   vb.org Archive > vBulletin Modifications > Archive > vB.org Archives > Premium Archives > ibProArcade Archive
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools
[Cheat] Bug found!!! Details »»
[Cheat] Bug found!!!
Version: , by the coldfusion the coldfusion is offline
Developer Last Online: Jan 2008 Show Printable Version Email this Page

Version: Unknown Rating:
Released: 02-19-2007 Last Update: Never Installs: 0
 
No support by the author.

Hi,
somebody i know, Refl3x, has found an exploit.
The exploit works like this: The score is submitted by a HTTP Post. If you create a form like this:
Code:
Edited, Pm me for the code!
This is a simple way to cheat. All you have to know is the exact name of the game.

Show Your Support

  • This modification may not be copied, reproduced or published elsewhere without author's permission.

Comments
  #12  
Old 02-22-2007, 04:20 AM
MrZeropage's Avatar
MrZeropage MrZeropage is offline
 
Join Date: Nov 2003
Location: Munich, Germany
Posts: 3,012
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Beside this I managed to fix all cross-scoring issues last night, one user already tested and verified that the fixes work.
I am somehow a little sad that nobody else wants to help and test for the cross-scoring-issue, I asked for some testusers two days ago and nobody wants to participate

I am now doing some adaptions to guest-play-feature and then v2.6.0+ is ready ... hope somebody else having cross-scoring-issues wants to test a pre-version of 2.6.0 (waiting for PM now)
Reply With Quote
  #13  
Old 02-22-2007, 04:29 AM
da420 da420 is offline
 
Join Date: Nov 2005
Posts: 1,232
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have not seen any cross scoring issues on my set up, so I am not sure if I can help, but if you need to test something I am always willing to do so Zero.
Reply With Quote
  #14  
Old 02-22-2007, 12:17 PM
MrZeropage's Avatar
MrZeropage MrZeropage is offline
 
Join Date: Nov 2003
Location: Munich, Germany
Posts: 3,012
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Before I even did not know how to cheat using cross-scoring, but after it got explained I verified it on my testsite.

But now this is eliminated, if anybody of those who reported the cross-scoring before could verify this is 100% fixed now. I am wondering as alot of people complained about it, and now that I want somebody to test and verify the fix, I am alone
Reply With Quote
  #15  
Old 02-22-2007, 12:23 PM
Shazz's Avatar
Shazz Shazz is offline
 
Join Date: Jun 2006
Location: Utah
Posts: 4,758
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

PM sent
Reply With Quote
  #16  
Old 02-22-2007, 12:30 PM
cashpath cashpath is offline
 
Join Date: Jul 2003
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by da420 View Post
I have not seen any cross scoring issues on my set up, so I am not sure if I can help, but if you need to test something I am always willing to do so Zero.
I beleive it was a bug with V3 games in your arcade.. I'm not positive on this but thats what I gathered from the testing.
Reply With Quote
  #17  
Old 02-22-2007, 03:58 PM
Stifmeister2 Stifmeister2 is offline
 
Join Date: Feb 2006
Location: Finland
Posts: 755
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yeah everyone who has knowledge of that cross-scoring issue in 2.5.9+ please contact MrZeropage!
Reply With Quote
  #18  
Old 02-23-2007, 05:57 AM
MrZeropage's Avatar
MrZeropage MrZeropage is offline
 
Join Date: Nov 2003
Location: Munich, Germany
Posts: 3,012
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

still nobody of those who reported this issue and waiting for a fix contacted me for testing... where is the ibProArcade-community ?!
Reply With Quote
  #19  
Old 02-23-2007, 09:01 PM
cashpath cashpath is offline
 
Join Date: Jul 2003
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Yeah everyone who has knowledge of that cross-scoring issue in 2.5.9+ please contact MrZeropage!
I did.. and I think he fixed it.. I think it is a different bug he is asking for people to help test. One I am not aware of.
Reply With Quote
  #20  
Old 02-24-2007, 01:01 PM
Stifmeister2 Stifmeister2 is offline
 
Join Date: Feb 2006
Location: Finland
Posts: 755
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I know one bug but I'm afraid it's impossible to fix it. (I've noticed Mr. Zeropage about it.)
Reply With Quote
  #21  
Old 02-24-2007, 03:17 PM
MrZeropage's Avatar
MrZeropage MrZeropage is offline
 
Join Date: Nov 2003
Location: Munich, Germany
Posts: 3,012
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That is not a bug but some external tool to manipulate communication between the player and the forum/server/arcade so nothing about the arcade itself...

but anyway, new secure games will somehow be protected against such manipulation
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:56 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.08571 seconds
  • Memory Usage 2,299KB
  • Queries Executed 25 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)bbcode_code
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)modsystem_post
  • (1)navbar
  • (6)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (11)post_thanks_box
  • (11)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (11)post_thanks_postbit_info
  • (10)postbit
  • (11)postbit_onlinestatus
  • (11)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete