Author Topic: Someone is bypassing permissions on the bug tracker!  (Read 7556 times)

Offline TechSY730

  • Core Member Mark V
  • *****
  • Posts: 4,570
Someone is bypassing permissions on the bug tracker!
« on: April 10, 2012, 11:53:00 pm »
Just as a warning in case you didn't notice, some dude named Buttons840 has been messing around with the supposedly disable priority field. (One example of an effected post is http://www.arcengames.com/mantisbt/view.php?id=824, though there are many others)

I've already created a new mantis issue about this type of attack itself (http://www.arcengames.com/mantisbt/view.php?id=7031)

Offline zespri

  • Hero Member Mark III
  • *****
  • Posts: 1,109
Re: Someone is bypassing permissions on the bug tracker!
« Reply #1 on: April 11, 2012, 12:46:07 am »
Everyone is at PAX anyway right now. Or has it finished?

Offline eRe4s3r

  • Core Member Mark II
  • *****
  • Posts: 2,825
Re: Someone is bypassing permissions on the bug tracker!
« Reply #2 on: April 11, 2012, 07:30:19 am »
Is Mantis coded in PHP?

That answers your question right there.  :o

PHP is not a web development language! (In fact, PHP is terrible, do not ever use it)
« Last Edit: April 11, 2012, 07:33:24 am by eRe4s3r »
Proud member of the Initiative for Bigger Weapons EV. - Bringer of Additive Blended Doom - Vote for Lore, get free cookie

Offline x4000

  • Chris McElligott Park, Arcen Founder and Lead Dev
  • Arcen Staff
  • Zenith Council Member Mark III
  • *****
  • Posts: 31,651
Re: Someone is bypassing permissions on the bug tracker!
« Reply #3 on: April 11, 2012, 08:17:33 am »
We keep mantis up to date with security patches. In this case I guess he set a field that was hidden, but which he had access to anyhow. Buttons840 is a good guy from my recollection, so I am not overly concerned on this specific case. It may simply be some sort of browser difference for all I know.
Have ideas or bug reports for one of our games?  Mantis for Suggestions and Bug Reports. Thanks for helping to make our games better!

Offline eRe4s3r

  • Core Member Mark II
  • *****
  • Posts: 2,825
Re: Someone is bypassing permissions on the bug tracker!
« Reply #4 on: April 11, 2012, 08:56:33 am »
But do you update PHP regularly as well? Well, at least expose_php = off is truly off ;p
« Last Edit: April 11, 2012, 08:59:56 am by eRe4s3r »
Proud member of the Initiative for Bigger Weapons EV. - Bringer of Additive Blended Doom - Vote for Lore, get free cookie

Offline x4000

  • Chris McElligott Park, Arcen Founder and Lead Dev
  • Arcen Staff
  • Zenith Council Member Mark III
  • *****
  • Posts: 31,651
Re: Someone is bypassing permissions on the bug tracker!
« Reply #5 on: April 11, 2012, 09:07:06 am »
But do you update PHP regularly as well? Well, at least expose_php = off is truly off ;p

We're on rackspace cloud sites, so that's really up to them.  But yes, I'm pretty sure they do.
Have ideas or bug reports for one of our games?  Mantis for Suggestions and Bug Reports. Thanks for helping to make our games better!

Offline keith.lamothe

  • Arcen Games Staff
  • Arcen Staff
  • Zenith Council Member Mark III
  • *****
  • Posts: 19,505
Re: Someone is bypassing permissions on the bug tracker!
« Reply #6 on: April 11, 2012, 10:30:18 am »
I would probably pay a couple of bucks for a book entitled "eRe4s3r's Opinion On Each Commonly Used (Alleged) Programming Language".  It would be hilarious.
Have ideas or bug reports for one of our games? Mantis for Suggestions and Bug Reports. Thanks for helping to make our games better!

Offline eRe4s3r

  • Core Member Mark II
  • *****
  • Posts: 2,825
Re: Someone is bypassing permissions on the bug tracker!
« Reply #7 on: April 11, 2012, 11:01:24 am »
Hehe

I don't really claim to be all knowing, but I do know a bit C, Perl and (less than a bit) PHP
That explains everything I think ;P

I mean.. == and === alone are one for the parody books.
PHP is also the only language that I intentionally dislike after trying it out.
Proud member of the Initiative for Bigger Weapons EV. - Bringer of Additive Blended Doom - Vote for Lore, get free cookie

Offline x4000

  • Chris McElligott Park, Arcen Founder and Lead Dev
  • Arcen Staff
  • Zenith Council Member Mark III
  • *****
  • Posts: 31,651
Re: Someone is bypassing permissions on the bug tracker!
« Reply #8 on: April 11, 2012, 11:08:01 am »
I dislike PHP as well, for the record, but it serves its purpose and it's not at the bottom of languages I dislike.
Have ideas or bug reports for one of our games?  Mantis for Suggestions and Bug Reports. Thanks for helping to make our games better!

Offline eRe4s3r

  • Core Member Mark II
  • *****
  • Posts: 2,825
Re: Someone is bypassing permissions on the bug tracker!
« Reply #9 on: April 11, 2012, 11:22:20 am »
queue the inevitable question..

What language you dislike the most.. the bottom 3 and why? ;p
Proud member of the Initiative for Bigger Weapons EV. - Bringer of Additive Blended Doom - Vote for Lore, get free cookie

Offline Hearteater

  • Core Member
  • *****
  • Posts: 2,334
Re: Someone is bypassing permissions on the bug tracker!
« Reply #10 on: April 11, 2012, 11:42:58 am »
I hate Lisp))))))))))))))))))))))))))))))))))))))))))))))))))))))))))

Offline x4000

  • Chris McElligott Park, Arcen Founder and Lead Dev
  • Arcen Staff
  • Zenith Council Member Mark III
  • *****
  • Posts: 31,651
Re: Someone is bypassing permissions on the bug tracker!
« Reply #11 on: April 11, 2012, 03:33:36 pm »
Well, there are a lot of languages that are really bad that I just stay away from because they are so incredibly bad I don't even want to work in them.  But out of the ones that are not complete trash, I really dislike Ruby.  And Torquescript.  And ColdFusion, though not with the fury that Keith does.
Have ideas or bug reports for one of our games?  Mantis for Suggestions and Bug Reports. Thanks for helping to make our games better!

Offline TechSY730

  • Core Member Mark V
  • *****
  • Posts: 4,570
Re: Someone is bypassing permissions on the bug tracker!
« Reply #12 on: April 11, 2012, 03:46:48 pm »
A candidate for one of the worst, non-joke language of all time, MUMPS!

Offline Hearteater

  • Core Member
  • *****
  • Posts: 2,334
Re: Someone is bypassing permissions on the bug tracker!
« Reply #13 on: April 11, 2012, 03:55:55 pm »
ColdFusion isn't bad, especially if you are using the latest version.  It is my primary language at work.  Not really my preference, but decent.  I have seen a TON of terrible code written in it through.  Replacing horrible CF code is a daily activity for me.  A lot of that comes from code written for earlier versions of CF though.  Scoping issues are a pain when people abuse cfinclude, they really need to improve query-of-query, and query typing and null handling needs to be fixed.  But otherwise it is a reasonable language.  I consider it mostly interchangeable with PHP.

Offline keith.lamothe

  • Arcen Games Staff
  • Arcen Staff
  • Zenith Council Member Mark III
  • *****
  • Posts: 19,505
Re: Someone is bypassing permissions on the bug tracker!
« Reply #14 on: April 11, 2012, 05:21:01 pm »
I worked a ColdFusion/MSSQL job for 5 years.  MSSQL I'm still on speaking terms with.  CF... care to hazard a guess at what "Branch Offset Too Long For Short" means?

But I'm pretty heavily biased, I dislike any language that doesn't have compile-time strong typing.  If it doesn't understand the source code before it runs it, I think there's something wrong ;)
Have ideas or bug reports for one of our games? Mantis for Suggestions and Bug Reports. Thanks for helping to make our games better!