Mysidia Adoptables Support Forum  

Home Community Mys-Script Creative Off-Topic
Go Back   Mysidia Adoptables Support Forum > Mysidia Adoptables > Questions and Supports

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 07-11-2012, 06:43 PM
SilverDragonTears's Avatar
SilverDragonTears SilverDragonTears is offline
I am your Nemesis.
 
Join Date: Jun 2011
Posts: 1,113
Gender: Female
Credits: 83,383
SilverDragonTears is on a distinguished road
Default Asked this b4 I think... adopt hole

If you use the URL http://taleofdragons.net/adopt.php?id=# and replace # with certain (low) numbers, you can adopt different dragons

I could never figure out how to prevent this :( Help please...
__________________

Check out SilvaTales
Reply With Quote
  #2  
Old 07-11-2012, 08:10 PM
Hall of Famer's Avatar
Hall of Famer Hall of Famer is offline
Administrator, Lead Coder
 
Join Date: Dec 2008
Location: South Brunswick
Posts: 4,448
Gender: Male
Credits: 367,838
Hall of Famer is on a distinguished road
Default

umm this problem still exists in Mys v1.3.x? Thought it was already fixed back in Mys v1.2.2, are you sure you are not using a heavily modified version of the script?

If you have this problem, you may fix this by adding a specific session variable to the doadopt page, or a hidden field value to the adoption form. This acts like a checkpoint to see if the user can adopt a certain pet.
__________________


Mysidia Adoptables, a free and ever-improving script for aspiring adoptables/pets site.
Reply With Quote
  #3  
Old 07-11-2012, 08:51 PM
Eldritch Eldritch is offline
Member
 
Join Date: Apr 2012
Posts: 3
Gender: Unknown/Other
Credits: 1,831
Eldritch is on a distinguished road
Default

It's still an issue. All someone would have to do to avoid this line (in adopt.php):
Code:
$_SESSION["allow"] = 1;
is enter the doadopt.php address while viewing adopt.php. It doesn't stop the abuse of adopt.php links at all, as adopt.php automatically sets that value to 1.
Reply With Quote
  #4  
Old 07-11-2012, 10:12 PM
Hall of Famer's Avatar
Hall of Famer Hall of Famer is offline
Administrator, Lead Coder
 
Join Date: Dec 2008
Location: South Brunswick
Posts: 4,448
Gender: Male
Credits: 367,838
Hall of Famer is on a distinguished road
Default

I see, so this is how they manage to get away from the session check... Looks like adoption session has to be redesigned, I will do it in a bit.
__________________


Mysidia Adoptables, a free and ever-improving script for aspiring adoptables/pets site.
Reply With Quote
  #5  
Old 07-11-2012, 11:06 PM
SilverDragonTears's Avatar
SilverDragonTears SilverDragonTears is offline
I am your Nemesis.
 
Join Date: Jun 2011
Posts: 1,113
Gender: Female
Credits: 83,383
SilverDragonTears is on a distinguished road
Default

Thanks Hof! It's pretty important for people not to be able to exploit this on my site and several members have already brought it to my attention that they know how to do so.
__________________

Check out SilvaTales
Reply With Quote
  #6  
Old 07-12-2012, 08:17 PM
Hall of Famer's Avatar
Hall of Famer Hall of Famer is offline
Administrator, Lead Coder
 
Join Date: Dec 2008
Location: South Brunswick
Posts: 4,448
Gender: Male
Credits: 367,838
Hall of Famer is on a distinguished road
Default

Well add this at the beginning of the script:(below the 'START SCRIPT' section):

PHP Code:
if(!isset($_GET['submit'])) throw new Exception('Direct access to this file is forbidden, please return to adopt.php and submit your form.'); 
__________________


Mysidia Adoptables, a free and ever-improving script for aspiring adoptables/pets site.
Reply With Quote
  #7  
Old 07-12-2012, 10:05 PM
Eldritch Eldritch is offline
Member
 
Join Date: Apr 2012
Posts: 3
Gender: Unknown/Other
Credits: 1,831
Eldritch is on a distinguished road
Default

Quote:
Originally Posted by Hall of Famer View Post
Well add this at the beginning of the script:(below the 'START SCRIPT' section):

PHP Code:
if(!isset($_GET['submit'])) throw new Exception('Direct access to this file is forbidden, please return to adopt.php and submit your form.'); 
The S in submit should be capitalized.

This has pretty much the same problem, only now the user has to add &Submit= to it, like /doadopt.php?id=1&Submit=.
Reply With Quote
  #8  
Old 07-12-2012, 11:50 PM
Hall of Famer's Avatar
Hall of Famer Hall of Famer is offline
Administrator, Lead Coder
 
Join Date: Dec 2008
Location: South Brunswick
Posts: 4,448
Gender: Male
Credits: 367,838
Hall of Famer is on a distinguished road
Default

I see, this is getting more and more series. How about changing the form method from GET to POST?
__________________


Mysidia Adoptables, a free and ever-improving script for aspiring adoptables/pets site.
Reply With Quote
  #9  
Old 07-13-2012, 08:34 AM
Tequila's Avatar
Tequila Tequila is offline
The Grim One
 
Join Date: Jan 2009
Location: Souther Tier, New York State
Posts: 1,356
Gender: Female
Credits: 98,368
Tequila is on a distinguished road
Default

Perhaps have a look at http://www.mysidiaadoptables.com/for...read.php?t=504 and see if any of that will help...

I'm planning on going back to a system like that once I get CH ready to launch.
__________________
Artist. Designer. Gamer. Mother.
[portfolio] [tarot] [Rune Hollow] [freebies]
Reply With Quote
  #10  
Old 07-13-2012, 09:51 AM
Eldritch Eldritch is offline
Member
 
Join Date: Apr 2012
Posts: 3
Gender: Unknown/Other
Credits: 1,831
Eldritch is on a distinguished road
Default

Quote:
Originally Posted by Hall of Famer View Post
I see, this is getting more and more series. How about changing the form method from GET to POST?
That would stop it from being a url problem and turn into a problem where users change the form values.

Quote:
Originally Posted by Nyxi View Post
Perhaps have a look at http://www.mysidiaadoptables.com/for...read.php?t=504 and see if any of that will help...

I'm planning on going back to a system like that once I get CH ready to launch.
I do not understand what that code is supposed to do, and so can't really say anything about it.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Adopt pages, and general adopt/index page :L blondbananamix Questions and Supports 26 07-22-2011 12:12 PM
FAQ - LOOK HERE FIRST for the answers to those questions that are asked over and over Seapyramid Questions and Supports 8 09-29-2010 11:34 PM
2 - column on Adopt page and my Adopt page? SieghartZeke Questions and Supports 2 10-12-2009 02:58 PM


All times are GMT -5. The time now is 08:20 PM.

Currently Active Users: 10789 (0 members and 10789 guests)
Threads: 4,080, Posts: 32,024, Members: 2,016
Welcome to our newest members, jolob.
BETA





What's New?

What's Hot?

What's Popular?


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
vBCommerce I v2.0.0 Gold ©2010, PixelFX Studios
vBCredits I v2.0.0 Gold ©2010, PixelFX Studios
Emoticons by darkmoon3636