in the New Scratcher system.
This is in AT because it is Advanced and it is a Topic.
New Scratchers can post links on scratch.mit.edu, right?
http://scratch.mit.edu/redirect/url?link=http://google.com
Firefox somehow got that url, except to a Dropbox, when I was lazily seeing if they updated the Block Library's ramshackle counter system.


Offline
Sidharth wrote:
shhhhh; we don't want spammers to hear this!
![]()
shhhhh; Magnie has a habit of using these redirects instead of directs!


Offline
Test: Stencyl
Offline
...Whoever invented the internet, stop fooling around with redirects.


Offline
I don't think the creators of the internet necessarily did it.
Offline
I knew about this for a while, but tried to keep quit. We don't need spammers hearing this stuff...
Offline
cocolover76 wrote:
Sidharth wrote:
shhhhh; we don't want spammers to hear this!
![]()
shhhhh; Magnie has a habit of using these redirects instead of directs!
![]()
Haha, since when?
It's because I can't do anything directly, no?
Offline
djdolphin wrote:
Hardmath123 wrote:
I knew about this for a while, but tried to keep quit. We don't need spammers hearing this stuff...
I knew about this for a long time too.
Firefox automatically took me to a redirect on Scratch to a image when I right clicked and clicked "View Image".


Offline
Does it work with images?
Nope.
Last edited by hello12345678910 (2012-01-29 10:35:41)
Offline
Offline
hello12345678910 wrote:
Does it work with images?
http://scratch.mit.edu/redirect/url?lin … p_edet.gif
Nope.
In fact, New Scratchers can't post images, even if they're from under scratch.mit.edu.
Offline
Maybe Bugs and Glitches is actually the place for this? It sounds like a bit of a security flaw. I'll request a move.
Offline
hello12345678910 wrote:
Does it work with images?
http://scratch.mit.edu/redirect/url?lin … p_edet.gif
Nope.
It did.
That's what all of the block library's block do (did, since [img] tags are turned off.
Offline
Hm, that is very interesting. It's also a spammer's dream
Offline
Wowzers, we gotta fix that.
Thanks for reporting it!
In the future, if you find security flaw like this one, please email us at help@scratch.mit.edu . And I'm not saying don't talk about it on the forums, but it is nice if you can give us a little lead time to fix it before anyone uses it to do something bad.
And, btw, I think we'll just leave this here for now while we sort it out.
Offline
bobbybee wrote:
Firefox wrote:
The page isn't redirecting properly
Firefox has detected that the server is redirecting the request for this address in a way that will never complete. This problem can sometimes be caused by disabling or refusing to accept cookies.
Edit: Why did Copy+Paste do that? Fixed.
Last edited by cocolover76 (2012-01-30 16:48:35)


Offline
Oh, also apparently, you use it everywhere.
Spamming programs could find it via searching in that "redirect" folder clearly mentioned here:
http://scratch.mit.edu/redirect wrote:
Closest match: scratch.mit.edu/redirect/about
Other things to try:
Go to scratch.mit.edu/redirect/share
Go to scratch.mit.edu/redirect/support


Offline
Ok, should be fixed now. Can you guys test it out?
Also, no need to go looking for vulnerabilities, but if you find one, please give us a patch too if you can! (But if you can't, just let us know.
Thanks!
Offline
cocolover76 wrote:
Oh, also apparently, you use it everywhere.
Spamming programs could find it via searching in that "redirect" folder clearly mentioned here:http://scratch.mit.edu/redirect wrote:
Closest match: scratch.mit.edu/redirect/about
Other things to try:
Go to scratch.mit.edu/redirect/share
Go to scratch.mit.edu/redirect/support
These are different (they aren't using the "url" function). They only redirect to a certain place.
Offline
SJRCS_011 wrote:
hello12345678910 wrote:
Does it work with images?
http://scratch.mit.edu/redirect/url?lin … p_edet.gif
Nope.It did.
That's what all of the block library's block do (did, since [url]tags are turned off.
actually they use antidote.
Offline