This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#1 2012-01-28 20:17:20

cocolover76
Scratcher
Registered: 2011-10-09
Posts: 500+

I found a weakness

in the New Scratcher system.
This is in AT because it is Advanced and it is a Topic.
New Scratchers can post links on scratch.mit.edu, right?

Code:

http://scratch.mit.edu/redirect/url?link=http://google.com

Firefox somehow got that url, except to a Dropbox, when I was lazily seeing if they updated the Block Library's ramshackle counter system.


http://i.imgur.com/HfEPZ.gifhttp://i.imgur.com/pvKb6.png

Offline

 

#2 2012-01-28 20:24:37

Sidharth
Scratcher
Registered: 2007-12-14
Posts: 100+

Re: I found a weakness

shhhhh; we don't want spammers to hear this!  tongue


http://www.danasoft.com/citysign.jpg

Offline

 

#3 2012-01-28 20:34:02

cocolover76
Scratcher
Registered: 2011-10-09
Posts: 500+

Re: I found a weakness

Sidharth wrote:

shhhhh; we don't want spammers to hear this!  tongue

shhhhh; Magnie has a habit of using these redirects instead of directs!  tongue


http://i.imgur.com/HfEPZ.gifhttp://i.imgur.com/pvKb6.png

Offline

 

#4 2012-01-28 21:31:35

ImagineIt_Test
New Scratcher
Registered: 2011-09-20
Posts: 1

Re: I found a weakness

Test: Stencyl

Offline

 

#5 2012-01-28 21:33:49

ImagineIt
Scratcher
Registered: 2011-02-28
Posts: 1000+

Re: I found a weakness

ImagineIt_Test wrote:

Test: Stencyl

Great! But what about this? Scratch

Last edited by ImagineIt (2012-01-28 21:34:07)

Offline

 

#6 2012-01-28 22:25:14

cocolover76
Scratcher
Registered: 2011-10-09
Posts: 500+

Re: I found a weakness

ImagineIt wrote:

ImagineIt_Test wrote:

Test: Stencyl

Great! But what about this? Scratch

...Whoever invented the internet, stop fooling around with redirects.


http://i.imgur.com/HfEPZ.gifhttp://i.imgur.com/pvKb6.png

Offline

 

#7 2012-01-28 22:31:26

soupoftomato
Scratcher
Registered: 2009-07-18
Posts: 1000+

Re: I found a weakness

cocolover76 wrote:

ImagineIt wrote:

ImagineIt_Test wrote:

Test: Stencyl

Great! But what about this? Scratch

...Whoever invented the internet, stop fooling around with redirects.

I don't think the creators of the internet necessarily did it.


I'm glad to think that the community will always be kind and helpful, the language will always be a fun and easy way to be introduced into programming, the motto will always be: Imagine, Program, Share - Nomolos

Offline

 

#8 2012-01-28 23:48:11

Hardmath123
Scratcher
Registered: 2010-02-19
Posts: 1000+

Re: I found a weakness

I knew about this for a while, but tried to keep quit. We don't need spammers hearing this stuff...


Hardmaths-MacBook-Pro:~ Hardmath$ sudo make $(whoami) a sandwich

Offline

 

#9 2012-01-29 00:28:04

Magnie
Scratcher
Registered: 2007-12-12
Posts: 1000+

Re: I found a weakness

cocolover76 wrote:

Sidharth wrote:

shhhhh; we don't want spammers to hear this!  tongue

shhhhh; Magnie has a habit of using these redirects instead of directs!  tongue

Haha, since when?  tongue

It's because I can't do anything directly, no?  wink

Offline

 

#10 2012-01-29 03:18:18

mattlai2
Scratcher
Registered: 2011-12-06
Posts: 100+

Re: I found a weakness

Wow... I love this!  tongue

The Scratch Team has to do something on this...

Offline

 

#11 2012-01-29 08:59:45

djdolphin
Scratcher
Registered: 2010-03-23
Posts: 100+

Re: I found a weakness

Hardmath123 wrote:

I knew about this for a while, but tried to keep quit. We don't need spammers hearing this stuff...

I knew about this for a long time too.

Offline

 

#12 2012-01-29 10:26:22

cocolover76
Scratcher
Registered: 2011-10-09
Posts: 500+

Re: I found a weakness

djdolphin wrote:

Hardmath123 wrote:

I knew about this for a while, but tried to keep quit. We don't need spammers hearing this stuff...

I knew about this for a long time too.

Firefox automatically took me to a redirect on Scratch to a image when I right clicked and clicked "View Image".


http://i.imgur.com/HfEPZ.gifhttp://i.imgur.com/pvKb6.png

Offline

 

#13 2012-01-29 10:35:08

hello12345678910
Scratcher
Registered: 2009-07-11
Posts: 100+

Re: I found a weakness

Does it work with images?

http://scratch.mit.edu/redirect/url?link=http://www.befria.nu/elias/pi/bitmap/pi_b_262144_desp_edet.gif

Nope.

Last edited by hello12345678910 (2012-01-29 10:35:41)


http://tinyurl.com/8yt32o9 http://tinyurl.com/6tgwp5r || Fish = F+I+S+H = 6+9+19+8 = 42<<The answer to Life, the Universe and Everything

Offline

 

#14 2012-01-29 10:56:33

TheDogIslandFan
Scratcher
Registered: 2012-01-08
Posts: 100+

Re: I found a weakness

Good one! Ha ha ha! (Just be quiet so the spammers won't hear)


http://www.eggcave.com/egg/787454.png

Offline

 

#15 2012-01-29 10:58:28

bobbybee
Scratcher
Registered: 2009-10-18
Posts: 1000+

Re: I found a weakness

tehehe  smile


I support the Free Software Foundation. Protect our digital rights!

Offline

 

#16 2012-01-29 11:16:50

mattlai2
Scratcher
Registered: 2011-12-06
Posts: 100+

Re: I found a weakness

hello12345678910 wrote:

Does it work with images?

http://scratch.mit.edu/redirect/url?lin … p_edet.gif

Nope.

In fact, New Scratchers can't post images, even if they're from under scratch.mit.edu.

Offline

 

#17 2012-01-29 14:11:06

sparks
Community Moderator
Registered: 2008-11-05
Posts: 1000+

Re: I found a weakness

Maybe Bugs and Glitches is actually the place for this? It sounds like a bit of a security flaw. I'll request a move.


http://img541.imageshack.us/img541/7563/scratchbetabanner.png

Offline

 

#18 2012-01-29 15:04:58

SJRCS_011
Scratcher
Registered: 2011-02-07
Posts: 1000+

Re: I found a weakness

hello12345678910 wrote:

Does it work with images?

http://scratch.mit.edu/redirect/url?lin … p_edet.gif

Nope.

It did.
That's what all of the block library's block do (did, since [img] tags are turned off.


http://i.imgur.com/vQqtH.png
Learning to Program in a Nutshell:  "You're missing a closing parentheses" - LS97

Offline

 

#19 2012-01-29 17:28:05

RedRocker227
Scratcher
Registered: 2011-10-26
Posts: 1000+

Re: I found a weakness

Hm, that is very interesting. It's also a spammer's dream  hmm


Why

Offline

 

#20 2012-01-30 15:35:11

Lightnin
Scratch Team
Registered: 2008-11-03
Posts: 1000+

Re: I found a weakness

Wowzers, we gotta fix that.  smile 
Thanks for reporting it!
In the future, if you find  security flaw like this one, please email us at help@scratch.mit.edu . And I'm not saying don't talk about it on the forums, but it is nice if you can give us a little lead time to fix it before anyone uses it to do something bad.
wink
And, btw, I think we'll just leave this here for now while we sort it out.


Help Scratchers make the leap to 2.0!
http://img818.imageshack.us/img818/6844/transitionteam.jpg

Offline

 

#21 2012-01-30 16:47:46

cocolover76
Scratcher
Registered: 2011-10-09
Posts: 500+

Re: I found a weakness

bobbybee wrote:

tehehe  smile

Firefox wrote:

The page isn't redirecting properly
Firefox has detected that the server is redirecting the request for this address in a way that will never complete. This problem can sometimes be caused by disabling or refusing to accept cookies.

Edit: Why did Copy+Paste do that? Fixed.

Last edited by cocolover76 (2012-01-30 16:48:35)


http://i.imgur.com/HfEPZ.gifhttp://i.imgur.com/pvKb6.png

Offline

 

#22 2012-01-30 16:50:12

cocolover76
Scratcher
Registered: 2011-10-09
Posts: 500+

Re: I found a weakness

Oh, also apparently, you use it everywhere.
Spamming programs could find it via searching in that "redirect" folder clearly mentioned here:

http://scratch.mit.edu/redirect wrote:

Closest match: scratch.­mit.­edu/­redirect/­about
Other things to try:

    Go to scratch.­mit.­edu/­redirect/­share
    Go to scratch.­mit.­edu/­redirect/­support


http://i.imgur.com/HfEPZ.gifhttp://i.imgur.com/pvKb6.png

Offline

 

#23 2012-01-30 16:54:59

Lightnin
Scratch Team
Registered: 2008-11-03
Posts: 1000+

Re: I found a weakness

Ok, should be fixed now. Can you guys test it out?

Also, no need to go looking for vulnerabilities, but if you find one, please give us a patch too if you can! (But if you can't, just let us know.  smile   

Thanks!


Help Scratchers make the leap to 2.0!
http://img818.imageshack.us/img818/6844/transitionteam.jpg

Offline

 

#24 2012-01-30 19:55:56

Lightnin
Scratch Team
Registered: 2008-11-03
Posts: 1000+

Re: I found a weakness

cocolover76 wrote:

Oh, also apparently, you use it everywhere.
Spamming programs could find it via searching in that "redirect" folder clearly mentioned here:

http://scratch.mit.edu/redirect wrote:

Closest match: scratch.­mit.­edu/­redirect/­about
Other things to try:

    Go to scratch.­mit.­edu/­redirect/­share
    Go to scratch.­mit.­edu/­redirect/­support

These are different (they aren't using the "url" function). They only redirect to a certain place.


Help Scratchers make the leap to 2.0!
http://img818.imageshack.us/img818/6844/transitionteam.jpg

Offline

 

#25 2012-01-31 02:03:56

joefarebrother
Scratcher
Registered: 2011-04-08
Posts: 1000+

Re: I found a weakness

SJRCS_011 wrote:

hello12345678910 wrote:

Does it work with images?

http://scratch.mit.edu/redirect/url?lin … p_edet.gif

Nope.

It did.
That's what all of the block library's block do (did, since [url]tags are turned off.

actually they use antidote.


My latest project is called http://tinyurl.com/d2m8hne! It has http://tinyurl.com/d395ygk views, http://tinyurl.com/cnasmt7 love-its, and http://tinyurl.com/bwjy8xs comments.
http://tinyurl.com/756anbk   http://tinyurl.com/iplaychess

Offline

 

Board footer