complaints

Forum > Complaints > Nothing as annoying :L
Reply To Thread (login)
2nd chance [36]
2013-04-23 09:40:28 🔗
[11 years, 247 days ago]

I once got a message of blh. It will not let me open the b-mail... Its like every time I log on I'm like yea a message same thing everyday for the past 3/4 days I've been excited to see what someone has put to me (Banter) But No its that fucking message any chance of the fucking off... I hope I'm allowed to use this sort of language here!


 
Leader [92]
2013-04-23 09:44:18 🔗
[11 years, 247 days ago]

A screen shot of Blh getting this trophy http://bots4.net/trophies/110


 
Fishwick [131]
Moderator
2013-04-23 09:46:39 🔗
[11 years, 247 days ago]

If its a message with no title (or it isn't clickable), right click and select 'Inspect Element' where the title should be. Then you should see a link, click it and it will open the mail


 
Lyrad [262]
2013-04-23 09:56:28 🔗
[11 years, 247 days ago]

can you show us a screenshot? so it's easy to verify what's wrong with it why it isnt readable.


 
2nd chance [36]
2013-04-23 10:00:37 🔗
[11 years, 247 days ago]

I've done the inspect element but still no link appears?? How do i screen shot?


 
2nd chance [36]
2013-04-23 10:03:06 🔗
[11 years, 247 days ago]

http://i.imgur.com/Jo7b2Wx.png


 
Lyrad [262]
2013-04-23 10:07:11 🔗
[11 years, 247 days ago]

how bout try clicking the background of the 2nd mail in the screenshot. then press tab until you get pass the arcane link in the 3rd line then press enter? you will know where the tab selects due to the doted square on the links that it goes.


 
2nd chance [36]
2013-04-23 10:13:24 🔗
[11 years, 247 days ago]

Omg I'm going to spunk all over your nipples Lyrad thank youu.... Hhahhahah Its GONE!!!!


 
Lyrad [262]
2013-04-23 10:14:58 🔗
[11 years, 247 days ago]

that's nice then!:) i just wondered how he did it though since ender coded the mails not to have blank titles.


 
Jans [87]
2013-04-23 10:19:47 🔗
[11 years, 247 days ago]

I see the warning message for empty subjects is still as subtle as ever..


 
Leader [92]
2013-04-23 10:43:13 🔗
[11 years, 247 days ago]

even though i logged into my account the bot your using and made it go ages ago thats why their wasn't any yellow N their


 
Solarisis [36]
2013-04-23 13:04:56 🔗
[11 years, 247 days ago]

It's strange, because the title I used was just a copy + paste from the fight with infant.. something like "infant is destroyed" or something like that.


 
Crab Whistler [64]
2013-04-23 13:30:28 🔗
[11 years, 247 days ago]


 
something2 [92]
2013-04-23 13:46:44 🔗
[11 years, 247 days ago]

 


 
Ender [1]
Administrator
2013-04-23 20:00:42 🔗
[11 years, 247 days ago]

I'll look into this. It's a bug that people can send bmails without titles.


 
Ender [1]
Administrator
2013-04-23 21:58:11 🔗
[11 years, 247 days ago]

This should be fixed - you should be able to open the bmail without any problems now.

The problem was that bmail titles weren't being escaped (!). This was a pretty blatant XSS vulnerability that I'm quite frankly am very surprised was never abused or taken advantage of (I checked the database). Methinks I need to start rewarding players for reporting what are (at least in my eyes) very obviously bugs...


 
2nd chance [36]
2013-04-24 07:47:32 🔗
[11 years, 247 days ago]

why is he so amazing^^


 
Jans [87]
2013-04-24 08:31:01 🔗
[11 years, 247 days ago]

Darnit, there goes my backdoor..


 
Ender [1]
Administrator
2013-04-24 08:58:28 🔗
[11 years, 246 days ago]

I wasn't sure from your post whether this was resolved for you, so I checked the server logs for accesses to that bmail. What I found confused me though: it looks like it's only been accessed once, by you, and at 09:42:27 server time yesterday, which is less than 2 minutes after you started this thread.

Am I overlooking something or did you figure out how to dig up the link from the page source on your own, but then continue to pretend you couldn't figure it out? :) (I'm really just genuinely curious)


 
User Name [288]
2013-04-24 09:26:16 🔗
[11 years, 246 days ago]

If you read up, apparently Leader informed him of the shift method of opening those pesky no header mails.


 
User Name [288]
2013-04-24 09:27:08 🔗
[11 years, 246 days ago]

Granted he informed him of that method an hour after the initial posting, not 2 minutes....


 
Leader [92]
2013-04-24 09:58:56 🔗
[11 years, 246 days ago]

i logged into my bot (2nd chance)he is using and got rid of it and then posted about it later if that helps


 
Ender [1]
Administrator
2013-04-24 21:57:59 🔗
[11 years, 246 days ago]

Aha, that would indeed explain the mystery, thanks! I didn't think to check the IP addresses - I see it was a different person that logged on and opened the bmail.


 
2nd chance [36]
2013-04-25 11:07:09 🔗
[11 years, 245 days ago]

I didn't realize it was gone and thought it was still there haha :)


 
Forum > Complaints > Nothing as annoying :L
Reply To Thread (login)