Discover Seattle!

General Category => Discover Seattle! => Topic started by: curses on Oct 18 06 02:38

Title: by the time you read this it might already be too late...
Post by: curses on Oct 18 06 02:38
DV will be back up again.

now remember all you junior script kiddies. some programmers forget to clean their data before they put it in the database. so what happens is that unscrupulous types (like yourselves ;) take advantage of this noobish trait by performing a SQL injection on the offending website.

i'm not saying that that is what happened but it might as well be the secenario. lol
 
Title: Re: by the time you read this it might already be too late...
Post by: Not Caring! on Oct 18 06 02:41
DV was down?

Actually, no need to answer, I don't care.
Title: Re: by the time you read this it might already be too late...
Post by: curses on Oct 18 06 02:42
lol. so this is the welcome i get on this so-called friendly website?

well that's more like then. woot!
 
Title: Re: by the time you read this it might already be too late...
Post by: TehBorken on Oct 18 06 02:43
  curses wrote:
DV will be back up again.

I didn't even realize it was down. I guess I was busy with other stuff. But thanks, I'll make a note on my calendar so I can start celebrating this great event next year.
 
Title: Re: by the time you read this it might already be too late...
Post by: tenkani on Oct 18 06 02:44
[font style="color: rgb(127, 0, 127);" size="7"]Curses!!![/font]  
Title: Re: by the time you read this it might already be too late...
Post by: TehBorken on Oct 18 06 02:44
  curses wrote:
lol. so this is the welcome i get on this so-called friendly website?

Who said this place was friendly? I checked the [a href="http://www.discoverseattle.net/w3c/tos.php"]TOS[/a] and didn't see the word "friendly' in there anywhere.
 
 
Title: Re: by the time you read this it might already be too late...
Post by: curses on Oct 18 06 02:45
 what's funny is the morons SQL injected themselves. check out the helpful error page i got when i tried posting.
[hr style="width: 100%; height: 2px;"]Microsoft VBScript compilation  error '800a0409'

Unterminated string constant

/forum/post_info.asp, line 1321

If strServerVariablesREMOTE_ADDR = "24.87.0.152
-----------------------------------------------^



   
Title: Re: by the time you read this it might already be too late...
Post by: TehBorken on Oct 18 06 02:47
 curses wrote:
 what's funny is the morons SQL injected themselves. check out the helpful error page i got when i tried posting.
[hr style="width: 100%; height: 2px;"]Microsoft VBScript compilation  error '800a0409'

Unterminated string constant

/forum/post_info.asp, line 1321

If strServerVariablesREMOTE_ADDR = "24.87.0.152
-----------------------------------------------^

[span style="background-color: rgb(255, 255, 0);"]LOL.[/span]

   
 
Title: Re: by the time you read this it might already be too late...
Post by: tenkani on Oct 18 06 02:48
Hay, for the technically incompetent like myself can you explain what all that jackamahoozits means?


EDIT:
[table style="font-family: Verdana,Arial,Helvetica; font-size: 10pt; color: midnightblue;" border="0" cellpadding="2" cellspacing="1" width="100%"][tbody][tr bgcolor="whitesmoke"][td align="center"](http://www.discovervancouver.com/forum/icon_folder.gif)[/td][td][a href="http://www.discovervancouver.com/forum/topic.asp?TOPIC_ID=112482"]Jesus, quiet day![/a][/td][td align="center"]blaimee [/td][td align="center"]3[/td][td align="center"]101[/td][td style="font-size: 7pt;" align="center" nowrap="nowrap"]10/18/2006
2:02:58 PM[/td][/tr][/tbody][/table]
Understatement of the year     ;)
 
Title: Re: by the time you read this it might already be too late...
Post by: TehBorken on Oct 18 06 02:51
 tenkani wrote:
Hay, for the technically incompetent like myself can you explain what all that jackamahoozits means?  

It means someone probably missed a quotation mark ("). An unterminated string is a string that is (erroneously) not delimited.

$mystring = "here is some text";   <--- correct


 $mystring = "here is some text;   <--- oopsie, no closing quote...
Title: Re: by the time you read this it might already be too late...
Post by: tenkani on Oct 18 06 02:52
Thanks!
So what does this mean?

If strServerVariablesREMOTE_ADDR = "24.87.0.152

I'm bored     ;)

 
Title: Re: by the time you read this it might already be too late...
Post by: purelife on Oct 18 06 02:58
I'm still confused but HI Curses and HI to tenkani.

  Miss ya both.  *hugs*
Title: Re: by the time you read this it might already be too late...
Post by: tenkani on Oct 18 06 03:00
I miss you both too!!!
But I miss you just a little bit more, PL, since Curses usually ignores me just to hear the sound of my heart breaking    :(......
 
Title: Re: by the time you read this it might already be too late...
Post by: purelife on Oct 18 06 03:18
It's actually pretty good that DV is at a standstill for the moment.  Then, I get the chance to read that Zfx thread.  

  Ummm, I'm not a good lier, am I?  ;)
Title: Re: by the time you read this it might already be too late...
Post by: curses on Oct 18 06 03:22
hi ho the merry-o

anyway. so the name of the variable tells me that this is how they filter out banned IP's. yeah and so they go the database and grab the banned IP's and throw them into a string everytime they use them. in this instance one of the IP's is probably malformed.
 
Title: Re: by the time you read this it might already be too late...
Post by: purelife on Oct 18 06 03:25
You're right about that curses.  When the Admins banned, they put the ip in a string.  I remember dogmeat explaining it to me when I had inquired if it was a simple process because I had wanted to bann people right on the spot as well.
Title: Re: by the time you read this it might already be too late...
Post by: tenkani on Oct 18 06 03:26
  Wow. So I'm guessing that some of the newer forum software has safety features that prevent this kind of thing? Like, if you malform your string it will tell you rather than just shutting the whole f*cking board down without your knowledge?

I guess what I'm asking is whether newer forum software will check your syntax before you finish making changes.
 
P.S. even now Curses delights in ignoring me. After all that we've been through, this is how he gets his kicks.

(http://www.motleycrow.com/ImageHost/doug-mutant-large.jpg)
Title: Re: by the time you read this it might already be too late...
Post by: curses on Oct 18 06 03:34
good programmers make sure their input is never malformed. but since DV programmers are script kids themselves i wouldn't have a clue what kind of best practices they use. if any. lol  
Title: Re: by the time you read this it might already be too late...
Post by: curses on Oct 18 06 03:36
p.s. the server running this software is lickety-split fast these days.  
Title: Re: by the time you read this it might already be too late...
Post by: tenkani on Oct 18 06 03:37
.....................
How do YOU like being ignored??
Shit, I blew it!     :(