Clan x86

Technical (Development, Security, etc.) => General Security Information => Topic started by: iago on January 05, 2006, 12:11:30 AM

Title: SMF Forum Exploit?
Post by: iago on January 05, 2006, 12:11:30 AM
It seems that you can fake the "last edit" tag, as I will demonstrate in this thread shortly :)

<edit> It should appear to be edited by Newby!
Title: Re: SMF Forum Exploit?
Post by: Ergot on January 05, 2006, 12:14:35 AM
omg hax... the poster of the thread turns into Newby @_@
Or well.. it did for a second... wait... all posts by iago said Newby :O
Title: Re: SMF Forum Exploit?
Post by: Quik on January 05, 2006, 12:56:46 AM
How is this done?

How is this meaningful, other than significant in the coding perspective?
Title: Re: SMF Forum Exploit?
Post by: iago on January 05, 2006, 01:00:38 AM
It's done with a clever trick I discovered, thanks to Ergot, in fact. 

The only real use of it is that you can frame somebody, or you can edit somebody else's post (as a moderator) without anybody knowing who edited the post.  This isn't major, but it can be useful in some cases. 
Title: Re: SMF Forum Exploit?
Post by: Ergot on January 05, 2006, 01:07:24 AM
Like for pranking! You silly goose!

iago poons you noob!
Title: Re: SMF Forum Exploit?
Post by: Newby on January 05, 2006, 09:00:02 AM
Is this where you change your display name, edit something, and post?

That's old, I did this on vL a while ago.

EDIT -- Notice the dot after my name? Yep. That's how I can tell it's either the same thing I've done or it's something totally new, seeing as how Ergot's one post was edited by "iago" and not "iago." :O!

And apparently the second coming of Christ has occured, he's edited my post!
Title: Re: SMF Forum Exploit?
Post by: iago on January 05, 2006, 10:21:23 AM
To most, the "." after the name looks like it's ending the sentence :P
Title: Re: SMF Forum Exploit?
Post by: Blaze on January 05, 2006, 12:25:12 PM
Oh, I thought it was something new and neat... but its just that old trick? You had my hopes up. :'(
Title: Re: SMF Forum Exploit?
Post by: trust on January 05, 2006, 07:51:09 PM
how do you do it
Title: Re: SMF Forum Exploit?
Post by: Quik on January 05, 2006, 08:46:27 PM
Quote from: OG Trust on January 05, 2006, 07:51:09 PM
how do you do it

Post, change your name, edit that post, then change your name back.
Title: Re: SMF Forum Exploit?
Post by: Sidoh on January 05, 2006, 09:18:47 PM
While this really isn't that big of a deal, I don't really see the point in them not implementing something to prevent it.

I personally think having the ability for the users to change their display name is stupid.  That's really the only problem I have with SMF, other than that, it's great software.
Title: Re: SMF Forum Exploit?
Post by: Newby on January 05, 2006, 09:30:16 PM
Quote from: Sidoh on January 05, 2006, 09:18:47 PM
I personally think having the ability for the users to change their display name is stupid.  That's really the only problem I have with SMF, other than that, it's great software.

I love it. It keeps them from making new accounts!

And you can disable name changing, which IIRC I had to enable again. :P
Title: Re: SMF Forum Exploit?
Post by: Sidoh on January 06, 2006, 01:00:10 AM
Quote from: Newby on January 05, 2006, 09:30:16 PM
Quote from: Sidoh on January 05, 2006, 09:18:47 PM
I personally think having the ability for the users to change their display name is stupid.  That's really the only problem I have with SMF, other than that, it's great software.

I love it. It keeps them from making new accounts!

And you can disable name changing, which IIRC I had to enable again. :P

If you need to change your name enough to where it's a serious need/want (like you've actually changed your handle), I think it would be easier to just request that an admin/mod change it.  That way you also avoid all of the extra complications that you get due to the ability to freely change it.
Title: Re: SMF Forum Exploit?
Post by: iago on January 06, 2006, 03:47:23 AM
I fully agree, and people were changing their display names to dumb things just to abuse the fact that it's annoying (Warrior comes to mind).  I really wish I could have turned it off, but ohwell.  Ergot also changed his to something annoying this week, but he found it got changed back on its own (*gasp*)!

But for this actual problem, it seems like it would make more sense storing the user_id of the last editor, not the username..
Title: Re: SMF Forum Exploit?
Post by: Ergot on January 06, 2006, 03:52:06 AM
I suspected it was either you or Newbis.