This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#1 2012-03-25 22:37:26

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

My new antidote script

I'm making my own antidote script.
It should be done in less than an hour.
Here's what it will support:

http://imageshack.us/x-image.png
[flash]flash_url_here[/flash]
[youtube]id[/youtube]
[scratch=flash]GeonoTRON2000/2416215[/scratch]

Last edited by GeonoTRON2000 (2012-04-06 21:12:56)


http://i.imgur.com/BAEgGDL.png

Offline

 

#2 2012-03-25 23:11:03

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

It's done!
Download here: http://www.cfagency.org/antidote.user.js
EDIT: HTML has been disabled.
ENJOY!

Last edited by GeonoTRON2000 (2012-03-26 10:34:39)


http://i.imgur.com/BAEgGDL.png

Offline

 

#3 2012-03-26 01:30:13

nathanprocks
Scratcher
Registered: 2011-04-14
Posts: 1000+

Re: My new antidote script

GeonoTRON2000 wrote:

It now passively enables HTML.
For example:
<input type="text" value="You can't do this in BBCode." />

This is very insecure. That is why Rookwood101 didn't put that in his code (and also made it hard to hack the tags to add code too).


http://carrot.cassiedragonandfriends.org/Scratch_Signature/randomsig.php
http://trinary.site40.net/images/scratchrank.php?username=nathanprocks&amp;display=small

Offline

 

#4 2012-03-26 10:03:25

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

nathanprocks wrote:

GeonoTRON2000 wrote:

It now passively enables HTML.
For example:
<input type="text" value="You can't do this in BBCode." />

This is very insecure. That is why Rookwood101 didn't put that in his code (and also made it hard to hack the tags to add code too).

Wassa da matta?  Afraid of a little IFrame?


http://i.imgur.com/BAEgGDL.png

Offline

 

#5 2012-03-26 10:13:03

Hardmath123
Scratcher
Registered: 2010-02-19
Posts: 1000+

Re: My new antidote script

<script type="text/javascript">
while(true)
{
alert("Nah, just this sort of thing.");
}
</script>


Hardmaths-MacBook-Pro:~ Hardmath$ sudo make $(whoami) a sandwich

Offline

 

#6 2012-03-26 10:28:58

Squawkers13
Scratcher
Registered: 2010-11-20
Posts: 500+

Re: My new antidote script

It can embed projects...
<tested>

Last edited by Squawkers13 (2012-03-26 10:29:39)


http://pekkit.net/banners/pekkit.png

Offline

 

#7 2012-03-26 10:45:12

ZeroLuck
Scratcher
Registered: 2010-02-23
Posts: 500+

Re: My new antidote script

GeonoTRON2000 wrote:

Wassa da matta?  Afraid of a little IFrame?

You can embed a script which posts automatical things on the forums and other bad things...


http://3.bp.blogspot.com/-oL2Atzp0Byw/T465vIQ36dI/AAAAAAAAADo/1vqL4PvhkM0/s1600/scratchdachwiki.png

Offline

 

#8 2012-03-26 10:49:12

zippynk
Scratcher
Registered: 2011-07-23
Posts: 500+

Re: My new antidote script

[img]http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");[/img]

Edit: I don't see an alert box. I guess it's secure.

Last edited by zippynk (2012-03-26 10:52:34)


https://dl.dropbox.com/u/60598636/trifocal_interlude_soundcloud_button.png

Offline

 

#9 2012-03-26 11:04:40

LS97
Scratcher
Registered: 2009-06-14
Posts: 1000+

Re: My new antidote script

Hardmath123 wrote:

<script type="text/javascript">
while(true)
{
alert("Nah, just this sort of thing.");
}
</script>

That's why you use Chrome -- it blocks multiple dialogue boxes!  big_smile

Offline

 

#10 2012-03-26 11:12:42

scimonster
Community Moderator
Registered: 2010-06-13
Posts: 1000+

Re: My new antidote script

LS97 wrote:

Hardmath123 wrote:

<script type="text/javascript">
while(true)
{
alert("Nah, just this sort of thing.");
}
</script>

That's why you use Chrome -- it blocks multiple dialogue boxes!  big_smile

FF gives you the option to stop them, but sometimes you want a few.  tongue

zippynk wrote:

http://4.bp.blogspot.com/-_oUAdpmJXpM/T … e.')"

Edit: I don't see an alert box. I guess it's secure.

Try now.

Offline

 

#11 2012-03-26 20:05:04

Squawkers13
Scratcher
Registered: 2010-11-20
Posts: 500+

Re: My new antidote script

<image>
http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");
<image>


http://pekkit.net/banners/pekkit.png

Offline

 

#12 2012-03-26 22:09:17

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

Squawkers13 wrote:

<image>
http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");
<image>

Actually, the BBCode is img, and so is the HTML tag.
[img]http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");[/img]


http://i.imgur.com/BAEgGDL.png

Offline

 

#13 2012-03-27 10:33:23

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

New scratch tag in the new version!

Code:

[scratch=flash]user/projectId[/scratch]

Last edited by GeonoTRON2000 (2012-04-12 23:09:09)


http://i.imgur.com/BAEgGDL.png

Offline

 

#14 2012-03-27 11:13:29

rookwood101
Scratcher
Registered: 2011-07-29
Posts: 500+

Re: My new antidote script

Do you think you could not call it antidote?

And also I don't see why you feel the need to remake something that has already been made, without adding any new features (well a few but not many) and it writing such an insecure version.

Last edited by rookwood101 (2012-03-27 11:15:03)


http://i.imgur.com/zeIZW.png

Offline

 

#15 2012-03-27 11:18:55

rookwood101
Scratcher
Registered: 2011-07-29
Posts: 500+

Re: My new antidote script

[img]http://www.silentrunners.org/graphics/sr/sr_5.gif" onload="alert('If you\'re seeing this in an alert box, the userscript isn\'t secure. Your password cookie: ' + document.cookie + 'I could quite easily send this to a third party source');[/img]

Last edited by rookwood101 (2012-03-27 11:24:38)


http://i.imgur.com/zeIZW.png

Offline

 

#16 2012-03-27 11:47:08

roijac
Scratcher
Registered: 2010-01-19
Posts: 1000+

Re: My new antidote script

[img]" /><img src="http://i.imgur.com/7lUPz.png" onload="while(true){alert('remove the script!')};" style="max-width: 510px;[/img]

Last edited by roijac (2012-04-07 16:17:23)

Offline

 

#17 2012-03-27 11:53:34

rookwood101
Scratcher
Registered: 2011-07-29
Posts: 500+

Re: My new antidote script


http://i.imgur.com/zeIZW.png

Offline

 

#18 2012-03-27 20:18:15

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

Teehee.  New version.  All onloads disabled.


http://i.imgur.com/BAEgGDL.png

Offline

 

#19 2012-03-28 00:51:01

lallaway12
Scratcher
Registered: 2012-01-04
Posts: 500+

Re: My new antidote script

hmm I will try this


http://i49.tinypic.com/2re4ied.png

Offline

 

#20 2012-03-28 01:36:50

roijac
Scratcher
Registered: 2010-01-19
Posts: 1000+

Re: My new antidote script

GeonoTRON2000 wrote:

Teehee.  New version.  All onloads disabled.

teehee. new image onload version. your code is still unsecure.

Offline

 

#21 2012-03-28 01:40:02

nathanprocks
Scratcher
Registered: 2011-04-14
Posts: 1000+

Re: My new antidote script

GeonoTRON2000 wrote:

Teehee.  New version.  All onloads disabled.

Did you disable the <script /> and <iframe />? (Yes, in-line frames can run JS too lol.)


http://carrot.cassiedragonandfriends.org/Scratch_Signature/randomsig.php
http://trinary.site40.net/images/scratchrank.php?username=nathanprocks&amp;display=small

Offline

 

#22 2012-03-28 10:35:47

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

This discussion is continued here: http://geonotron.net84.net/forums/viewt … =6&t=3


http://i.imgur.com/BAEgGDL.png

Offline

 

#23 2012-03-28 10:41:45

rookwood101
Scratcher
Registered: 2011-07-29
Posts: 500+

Re: My new antidote script

GeonoTRON2000 wrote:

This discussion is continued here: http://geonotron.net84.net/forums/viewt … =6&t=3

Why?


http://i.imgur.com/zeIZW.png

Offline

 

#24 2012-03-28 11:08:19

lallaway12
Scratcher
Registered: 2012-01-04
Posts: 500+

Re: My new antidote script

close topic


http://i49.tinypic.com/2re4ied.png

Offline

 

#25 2012-03-28 18:27:02

GeonoTRON2000
Scratcher
Registered: 2009-12-24
Posts: 1000+

Re: My new antidote script

rookwood101 wrote:

GeonoTRON2000 wrote:

This discussion is continued here: http://geonotron.net84.net/forums/viewt … =6&t=3

Why?

'Cuz this might be considered spam or something and this topic is likely to be closed.


http://i.imgur.com/BAEgGDL.png

Offline

 

Board footer