CodeWalrus

General => Other => Topic started by: Dream of Omnimaga on October 21, 2016, 03:50:24 AM

Title: 12test (IRC colors in post notifications or how to be banned)
Post by: Dream of Omnimaga on October 21, 2016, 03:50:24 AM
Test (I was wondering if that worked)
Title: Re: by01DJ Omnimaga10on by01DJ Omnimaga10on by01DJ Omnimaga10on on on on on on
Post by: kotu on October 21, 2016, 03:52:22 AM
A test of what you could do without being killed?
Title: 04H08o09w 11t12o 13g04e08t 09p11e12r13m04b08a09n11n12e13d
Post by: Dream of Omnimaga on October 21, 2016, 03:59:09 AM
Somewhat. Anyway I was testing if IRC color codes worked in topic titles because on Omnimaga they did so the post bot showed them :trollface:

But obviously it needs to not fall under the wrong hands <_<
Title: Re: \x08test (IRC colors in post notifications or how to be banned)
Post by: p2 on October 21, 2016, 08:45:03 AM
you should move it to savehacen so newbies dont find out about this... :P
(http://img.codewalr.us/permban.png)
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: novenary on October 21, 2016, 10:59:00 AM
Yeah the title is passed straight through to IRC by the bot. I don't think it's something worth bothering with. :P
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: Travis on October 21, 2016, 01:46:00 PM
Heh, I hadn't thought of it being possible to stick control characters in topics. With ^A, it may be possible to fool a bot into making arbitrary CTCPs (or mess up the CTCP /me's it's already trying to send). :P
Title: asdfPRIVMSG #CodeWalrus :the game
Post by: Sorunome on October 21, 2016, 01:48:09 PM
testing for security leak
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: Dream of Omnimaga on October 21, 2016, 02:14:40 PM
I remember back when Omni post bot was a SMF mod and had that exploit allowing me to post THE GAMEvia the bot <_<
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: novenary on October 21, 2016, 09:19:21 PM
SMF strips new lines so it should be pretty safe considering we prefix the title with some text.
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: Dream of Omnimaga on October 21, 2016, 09:48:18 PM
Actually, the exploit I am talking about was basically this: The post notification was sent by running a PHP file with URL parameters. Anyone who knew the URL and required arguments could send any text from the post notifier at will by opening the file URL in their browser. That was somewhere in 2011, hence why I was a bit against making CW bot a PHP script at first. But as an admin, it was fun while it lasted :trollface: .
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: c4ooo on October 21, 2016, 09:53:27 PM
Lol, this is pretty aswome xD Reminds me of when Commisar Snektron was experimenting with sending colour codes via Minecraft chat. (Which didn't work)
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: Dream of Omnimaga on October 22, 2016, 12:25:36 AM
I think they would only have worked on IRC and perhaps Omnom/WIRC. :P


Also, I remember having fun with ASCII art using background colors. I was posting Mario sprites, but then someone posted goatse of Homer Simpson in ASCII-art form (oh and don't google it if you're under 18 x.x)
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: p2 on October 23, 2016, 05:55:16 PM
was searching for "goatse of Homer Simpson" just out of curiosity (didnt know what I should expect so I just tried it).
Half of the results is stuff carved into pumpkins...  O.O
I guess I misunderstood something as it's not my mother language ^^

That was my favorite one: :3
[spoiler](http://weknowmemes.com/wp-content/uploads/2011/10/pedobear-pumpkin-carving2.jpg)[/spoiler]
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: novenary on October 23, 2016, 06:42:03 PM
Quote from: DJ Omnimaga on October 21, 2016, 09:48:18 PM
Actually, the exploit I am talking about was basically this: The post notification was sent by running a PHP file with URL parameters. Anyone who knew the URL and required arguments could send any text from the post notifier at will by opening the file URL in their browser. That was somewhere in 2011, hence why I was a bit against making CW bot a PHP script at first. But as an admin, it was fun while it lasted :trollface: .
Technically that's what the bot does, but it only accepts connections from localhost. I sometimes make it say the game. :P
Title: 04Re: test (IRC colors in post notifications or how to be banned)
Post by: Dream of Omnimaga on October 24, 2016, 03:26:25 AM
Quote from: Streetwalrus on October 23, 2016, 06:42:03 PM
Quote from: DJ Omnimaga on October 21, 2016, 09:48:18 PM
Actually, the exploit I am talking about was basically this: The post notification was sent by running a PHP file with URL parameters. Anyone who knew the URL and required arguments could send any text from the post notifier at will by opening the file URL in their browser. That was somewhere in 2011, hence why I was a bit against making CW bot a PHP script at first. But as an admin, it was fun while it lasted :trollface: .
Technically that's what the bot does, but it only accepts connections from localhost. I sometimes make it say the game. :P
Ah I see. At least it's kinda secure at least. And yes you made me lose often with it <_<

Quote from: p2 on October 23, 2016, 05:55:16 PM
was searching for "goatse of Homer Simpson" just out of curiosity (didnt know what I should expect so I just tried it).
Half of the results is stuff carved into pumpkins...  O.O
I guess I misunderstood something as it's not my mother language ^^

That was my favorite one: :3
[spoiler](http://weknowmemes.com/wp-content/uploads/2011/10/pedobear-pumpkin-carving2.jpg)[/spoiler]
That is scary O.O. I guess it's a good thing, though, because what the shock site was is truly NSFW and 18+ content that is somewhat gruesome as well O.O
Title: Re: 12test (IRC colors in post notifications or how to be banned)
Post by: Yuki on October 24, 2016, 03:44:15 AM
Quote from: Streetwalrus on October 23, 2016, 06:42:03 PM
Quote from: DJ Omnimaga on October 21, 2016, 09:48:18 PM
Actually, the exploit I am talking about was basically this: The post notification was sent by running a PHP file with URL parameters. Anyone who knew the URL and required arguments could send any text from the post notifier at will by opening the file URL in their browser. That was somewhere in 2011, hence why I was a bit against making CW bot a PHP script at first. But as an admin, it was fun while it lasted :trollface: .
Technically that's what the bot does, but it only accepts connections from localhost. I sometimes make it say the game. :P
Yeah, basically the exploit is there, the bot itself does not check who sent stuff to it, but it only accepts connections from localhost. So, basically, you'd need to be either have access to the server or abuse another exploit that would probably result in a CVE number being assigned to it.