Tuesday, 26. November 2002
hns,
November 26, 2002 at 10:36:54 AM CET
Not a theoretical exploit What you see above, if you see anything, are your Antville credentials. Instead of displaying them to you, I could have sent them to myself without you noticing anything strange. Owning these keys, I could have logged in to your antville.org account and do everything you are allowed to do on antville, writing under your name and editing and deleting everything you are able to edit and delete. Until last week's fix, that is. As Robert explained, we fixed this very real vulnerability by making your cookies work only with the IP address they originally come from. Unfortunately some people decided to go mad when they lost a story or comment while we were converting to the new scheme, or due to login problems with the new scheme. I'd like to remind these people that outages like these are bound to happen here on antville.org due to its evolutionary nature, and if they can't accept this fact they should start looking for a different hosting opportunity. For all the others, we are making an effort to make Helma and Antville more secure and comfortable. Everybody's help and comments are welcome. I know the frustration of losing a well-crafted text, but whining is not a long-term option and will generally not do very much good. |
The Antville Server Fund has been a great success. Thanks to everybody who contributed!
online for 8549 Days
last updated: 1/4/11, 10:22 AM Youre not logged in ... Login
... home
... topics ... galleries ... Home
... Tags
... Galleries
... about antville ... download ... macros.antville.org ... help.antville.org ... translate antville! ... antville home
i understand your concerns however,
i hardly can think of a solution. certainly, if the...
by tobi (7/29/03, 9:47 AM)
Found several more similar sites
listed This is getting to be quite a concern to...
by cobalt123 (7/27/03, 7:56 PM)
Second Post Alert on Referrer
bug livecatz I put this into "help" and now here:...
by cobalt123 (7/26/03, 7:14 PM)
well it's not easy to
find from here, anyway. think we should include a link,...
by tobi (7/24/03, 11:25 AM)
clock not that it's particularly
earthshattering but the antclock is running slow by about 15...
by kohlehydrat (7/23/03, 8:25 PM)
How to log skin names
I accessed to console?? Hi, I would like to know...
by winson (7/23/03, 4:12 PM)
|