Points of Required Attention™
Please chime in on a proposed restructuring of the ROM hacking sections.
Views: 88,589,195
Main | FAQ | Uploader | IRC chat | Radio | Memberlist | Active users | Latest posts | Calendar | Stats | Online users | Search 05-16-24 12:35 AM
Guest: Register | Login

Main - Posts by Mega-Mario

Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47

Mega-Mario
Posted on 02-18-10 04:29 PM, in ¿ʎɐpoʇ ǝʍ ǝɹɐ ʍoɥ Link | Quote | ID: 127255

Spamming from alt accounts.
Level: 81

Posts: 654/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
The source will reveal the meaning of the message...

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-18-10 11:09 PM, in ¿ʎɐpoʇ ǝʍ ǝɹɐ ʍoɥ Link | Quote | ID: 127285

Spamming from alt accounts.
Level: 81

Posts: 655/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days


____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-19-10 08:05 PM, in The Shiny New Layout Thread! (rev. 3 of 02-19-10 09:56 PM) Link | Quote | ID: 127335

Spamming from alt accounts.
Level: 81

Posts: 657/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
More awesome layout: colors are selected randomly!

Just found the way to make it apply to the light block as well.

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-19-10 10:12 PM, in The Shiny New Layout Thread! (rev. 2 of 02-19-10 10:13 PM) Link | Quote | ID: 127341

Spamming from alt accounts.
Level: 81

Posts: 658/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Fixed. Thank you

Also, I made a PHP script that generates a CSS stylesheet with random color attributes.

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-20-10 09:51 PM, in ¿ʎɐpoʇ ǝʍ ǝɹɐ ʍoɥ Link | Quote | ID: 127363

Spamming from alt accounts.
Level: 81

Posts: 659/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days


____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-20-10 11:43 PM, in ¿ʎɐpoʇ ǝʍ ǝɹɐ ʍoɥ Link | Quote | ID: 127366

Spamming from alt accounts.
Level: 81

Posts: 660/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Hehe, blank response! I got you!


____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-21-10 02:21 AM, in ¿ʎɐpoʇ ǝʍ ǝɹɐ ʍoɥ (rev. 2 of 02-21-10 02:22 AM) Link | Quote | ID: 127374

Spamming from alt accounts.
Level: 81

Posts: 661/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Here's yet another variant.


____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-21-10 05:20 PM, in New Retro Mario Bros. (Jceggbert5 Edition) (NSMB NDS) Link | Quote | ID: 127390

Spamming from alt accounts.
Level: 81

Posts: 662/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Nevermind, it looked bad. And I replaced it with something else...

Back on topic.

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-21-10 05:28 PM, in ¿ʎɐpoʇ ǝʍ ǝɹɐ ʍoɥ Link | Quote | ID: 127392

Spamming from alt accounts.
Level: 81

Posts: 663/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Ṍḳḁẏ, ḹḝṱ'ṧ ḅḙ ṃṍṙḗ ḉṙḕḁṭḭṿḙ ṅṏẉ...

/ḿḛ ḧṵḡṩ ṯḣḛ Ḉḣḁṟḁḉṫḗṙ Ṃḁṗ

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-21-10 05:35 PM, in The Shiny New Layout Thread! Link | Quote | ID: 127393

Spamming from alt accounts.
Level: 81

Posts: 664/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
You should. PHP is a really great thing. You don't imagine what you can do with it.

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-22-10 01:49 PM, in Post Layouts, Javascript, CSS and IE <7 (rev. 2 of 02-22-10 01:50 PM) Link | Quote | ID: 127439

Spamming from alt accounts.
Level: 81

Posts: 666/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Or can't we just go and make the board unusable under IE<7?

Because IE6 is the vulnerability. Seriously why does it let you do things like <img src="javascript:alert('foo');">??

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-22-10 01:57 PM, in <GreyMario> literally like fifteen minutes in mspaint (GreyMario's Art Dump) Link | Quote | ID: 127441

Spamming from alt accounts.
Level: 81

Posts: 668/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Nice
Something catches my attention with the room though, why is that door so low/small compared to the character in the room?

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-22-10 10:14 PM, in Post Layouts, Javascript, CSS and IE <7 (rev. 3 of 02-22-10 10:19 PM) Link | Quote | ID: 127461

Spamming from alt accounts.
Level: 81

Posts: 670/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
But wait, that's even worse than the <img> trick...

The W3Schools website says that the width property can be either inherited, auto, a percentage or a length in px/cm/etc...

That seems like yet another IE-specific crap... serisouly... why does Micro$oft always bother adding nonstandard crap in their browser rather than making it respect CSS standards? It's just a waste of time, because noone is ever going to use that crap because they know it will only work under IE!

And I wasted my 666th post...

Edit- there's another problem. This one issue might be hard to filter because it can be in an external stylesheet (like it's the case here). It'd require opening the stylesheet in question and removing its inclusion if it contains JS.

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-23-10 12:19 AM, in Post Layouts, Javascript, CSS and IE <7 Link | Quote | ID: 127470

Spamming from alt accounts.
Level: 81

Posts: 671/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Posted by blackhole89
banning external stylesheets

NO!



Another alternative would require the board to download the stylesheet, look for JS in it and remove its inclusion if there's any. But that'd be tricky.

Posted by blackhole89
Does this problem affect decent browsers too or is this only something IE has come up with?

No, it doesn't affect decent CSS-compliant browsers, of course. It only affects IE because Micro$oft always comes up with nonstandard crap that makes their browser and everything vulnerable

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-23-10 07:15 PM, in Post Layouts, Javascript, CSS and IE <7 Link | Quote | ID: 127495

Spamming from alt accounts.
Level: 81

Posts: 673/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Those are all good ideas, Kawa.

Except for the first point, what if the browser is disguising as another browser by a changed user agent? though, I don't think IE can do that...

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-23-10 11:35 PM, in Post Layouts, Javascript, CSS and IE <7 Link | Quote | ID: 127515

Spamming from alt accounts.
Level: 81

Posts: 677/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Posted by GreyMario
Why the hell would you need to disguise as IE6 on a site that works just fine in any reputable browser ever?

Allright, it'd be a rather bad idea.

Posted by Arbe
this board was written by people with no idea about real security, then maintained by someone who, looking back on the board's history, learned design security from XSS cheat sheets. it'll never be vulnerability free.

Allright. Look at the Acmlmboard source code of 1.x versions. Look at how user input is sanitized before being passed to SQL queries. Strings are addslashes()'d and integers aren't even sanitized! omg.

According to what I can read from the archives, they also didn't know what database backups were for. And when they were getting hacked, they always went "oh, due to an unfortunate event the board has been restored from a 3 year old backup... if some things are missing feel free to ask us "



____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-24-10 12:36 AM, in Post Layouts, Javascript, CSS and IE <7 Link | Quote | ID: 127524

Spamming from alt accounts.
Level: 81

Posts: 681/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Hm, yeah, but how would a PHP script called by the vulnerability set a flag that the page's script could read while it's still loading?

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-24-10 12:45 AM, in Post Layouts, Javascript, CSS and IE <7 (rev. 2 of 02-24-10 12:46 AM) Link | Quote | ID: 127527

Spamming from alt accounts.
Level: 81

Posts: 683/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Ah, now I see. It'd be something like that
body { width:expression(document.cookie+='; usingcrap=1'); }


And then,
if ($_COOKIE["usingcrap"]==1) $removelayouts = 1;


____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-26-10 12:36 PM, in How's The Weather? Link | Quote | ID: 127640

Spamming from alt accounts.
Level: 81

Posts: 699/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Rainy, ugly, but sunny from times to times.
Also, crazy wind during this night

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit

Mega-Mario
Posted on 02-26-10 03:16 PM, in Winter Mosts 2010 - Discussion (rev. 2 of 02-26-10 03:17 PM) Link | Quote | ID: 127644

Spamming from alt accounts.
Level: 81

Posts: 701/1610
EXP: 4888482
Next: 104367

Since: 09-10-08

Last post: 3609 days
Last view: 3029 days
Posted by GreyMario
Surely not ALL of our layouts suck, NightKev.

Allright. People at Neritic Net seem to like mine. (note that there, it's much more complete with sidebars and all)

____________________
Kafuka -- ROM hacking
Kuribo64 -- we hack shit
Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47


Main - Posts by Mega-Mario

Acmlmboard 2.1+4δ (2023-01-15)
© 2005-2023 Acmlm, blackhole89, Xkeeper et al.

Page rendered in 0.677 seconds. (335KB of memory used)
MySQL - queries: 32, rows: 64/64, time: 0.663 seconds.