Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. O boy. Yet another CPhog oddity.

O boy. Yet another CPhog oddity.

Scheduled Pinned Locked Moved The Lounge
databasecomquestion
10 Posts 6 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A Offline
    A Offline
    Anton Afanasyev
    wrote on last edited by
    #1

    WARNING: DONT TRY WHAT I DESCRIBED UNLESS YOU WANT TO KILL CP SERVERS. AT LEAST, DONT ALL TRY THIS AT ONCE. And a pretty bad one at that. Take any thread in the Lounge (may work with other forums, but I didnt dare try after it happened to me in the Lounge). See the "View Thread" button? Click it. A page opens, with that thread. Now, look up in the address bar. See the "tid" query parameter? Change it to something that wouldn't appear in the Lounge. Such as "1". SO you will have something like http://codeproject.com/Lounge.aspx?fid=1159&tid=1 Now click on the refresh button added by CPhog to the top of the forum (near the "New Message" link, except more centered). And...WATCH AS ALL THE LOUNGE MESSAGES START LOADING. THIS IS MADNESS!!! I hope CP servers dont take too much of a hit cause of this :~

    :badger:

    G 1 Reply Last reply
    0
    • A Anton Afanasyev

      WARNING: DONT TRY WHAT I DESCRIBED UNLESS YOU WANT TO KILL CP SERVERS. AT LEAST, DONT ALL TRY THIS AT ONCE. And a pretty bad one at that. Take any thread in the Lounge (may work with other forums, but I didnt dare try after it happened to me in the Lounge). See the "View Thread" button? Click it. A page opens, with that thread. Now, look up in the address bar. See the "tid" query parameter? Change it to something that wouldn't appear in the Lounge. Such as "1". SO you will have something like http://codeproject.com/Lounge.aspx?fid=1159&tid=1 Now click on the refresh button added by CPhog to the top of the forum (near the "New Message" link, except more centered). And...WATCH AS ALL THE LOUNGE MESSAGES START LOADING. THIS IS MADNESS!!! I hope CP servers dont take too much of a hit cause of this :~

      :badger:

      G Offline
      G Offline
      Gary Wheeler
      wrote on last edited by
      #2

      Instead of posting an issue/vulnerability like this in a public place, why not just e-mail it to Chris? That way he has a chance to deal with it, instead of the DOS attacks from the juvenile trolls and script kiddies who like to piss on everything.


      Software Zen: delete this;

      E 1 Reply Last reply
      0
      • G Gary Wheeler

        Instead of posting an issue/vulnerability like this in a public place, why not just e-mail it to Chris? That way he has a chance to deal with it, instead of the DOS attacks from the juvenile trolls and script kiddies who like to piss on everything.


        Software Zen: delete this;

        E Offline
        E Offline
        Ed Poore
        wrote on last edited by
        #3

        How about emailing it to Shog since he's the one in charge of the scripts?


        My Blog[^]

        G 1 Reply Last reply
        0
        • E Ed Poore

          How about emailing it to Shog since he's the one in charge of the scripts?


          My Blog[^]

          G Offline
          G Offline
          Gary Wheeler
          wrote on last edited by
          #4

          I don't use CPhog (I use IE). The problem sounded like an issue with the query parameter handling implemented by CP, rather than CPhog's use of it. If the bug is actually in CPhog, then of course Shog9 should hear about it.

          Software Zen: delete this;

          P 1 Reply Last reply
          0
          • G Gary Wheeler

            I don't use CPhog (I use IE). The problem sounded like an issue with the query parameter handling implemented by CP, rather than CPhog's use of it. If the bug is actually in CPhog, then of course Shog9 should hear about it.

            Software Zen: delete this;

            P Offline
            P Offline
            Pete OHanlon
            wrote on last edited by
            #5

            Gary Wheeler wrote:

            course Shog9

            Nice use of the Superscript and colouration there. It's the little touches like this that define a post.

            Deja View - the feeling that you've seen this post before.

            My blog | My articles

            G 1 Reply Last reply
            0
            • P Pete OHanlon

              Gary Wheeler wrote:

              course Shog9

              Nice use of the Superscript and colouration there. It's the little touches like this that define a post.

              Deja View - the feeling that you've seen this post before.

              My blog | My articles

              G Offline
              G Offline
              Gary Wheeler
              wrote on last edited by
              #6

              Thanks :-\. It's the online version of pronouncing someone's name correctly. I just think it's the polite thing to do.

              Software Zen: delete this;

              M P 2 Replies Last reply
              0
              • G Gary Wheeler

                Thanks :-\. It's the online version of pronouncing someone's name correctly. I just think it's the polite thing to do.

                Software Zen: delete this;

                M Offline
                M Offline
                martin_hughes
                wrote on last edited by
                #7

                I quite agree - good point Jerry Whaler.

                "On one of my cards it said I had to find temperatures lower than -8. The numbers I uncovered were -6 and -7 so I thought I had won, and so did the woman in the shop. But when she scanned the card the machine said I hadn't. "I phoned Camelot and they fobbed me off with some story that -6 is higher - not lower - than -8 but I'm not having it." -Tina Farrell, a 23 year old thicky from Levenshulme, Manchester.

                G 1 Reply Last reply
                0
                • M martin_hughes

                  I quite agree - good point Jerry Whaler.

                  "On one of my cards it said I had to find temperatures lower than -8. The numbers I uncovered were -6 and -7 so I thought I had won, and so did the woman in the shop. But when she scanned the card the machine said I hadn't. "I phoned Camelot and they fobbed me off with some story that -6 is higher - not lower - than -8 but I'm not having it." -Tina Farrell, a 23 year old thicky from Levenshulme, Manchester.

                  G Offline
                  G Offline
                  Gary Wheeler
                  wrote on last edited by
                  #8

                  :laugh: Around where I live (Xenia, Ohio, US), it's usually pronounced as if it were spelled "Gerry Whuller" :rolleyes:.

                  Software Zen: delete this;

                  1 Reply Last reply
                  0
                  • G Gary Wheeler

                    Thanks :-\. It's the online version of pronouncing someone's name correctly. I just think it's the polite thing to do.

                    Software Zen: delete this;

                    P Offline
                    P Offline
                    Pete OHanlon
                    wrote on last edited by
                    #9

                    It amazes me how many people here know how my name is spelt, but people I went to school with still get it wrong. Woohoo - way to go CP, you guys really are a higher lifeform. ;)

                    Deja View - the feeling that you've seen this post before.

                    My blog | My articles

                    D 1 Reply Last reply
                    0
                    • P Pete OHanlon

                      It amazes me how many people here know how my name is spelt, but people I went to school with still get it wrong. Woohoo - way to go CP, you guys really are a higher lifeform. ;)

                      Deja View - the feeling that you've seen this post before.

                      My blog | My articles

                      D Offline
                      D Offline
                      Dan Neely
                      wrote on last edited by
                      #10

                      or maybe your classmates just didn't have copy/paste available. :rolleyes:

                      Otherwise [Microsoft is] toast in the long term no matter how much money they've got. They would be already if the Linux community didn't have it's head so firmly up it's own command line buffer that it looks like taking 15 years to find the desktop. -- Matthew Faithfull

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups