This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#51 2012-10-02 09:59:39

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

chongyian wrote:

Not trying to interfere, but ... OMG! XenoK! you are from singapore too?

Im from the US


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#52 2012-10-02 11:45:22

P110
Scratcher
Registered: 2011-04-12
Posts: 500+

Re: EternityX1 Development Topic

XenoK wrote:

We are prolly gonna add recaptcha tothe signup page when i make that.  I want you to make some security enhancements to what we have, and proof checking the current new user files.  I have on my calendar to make enhancements to the user_edit.php file today, i already have some things in mind.

ok


Me live on 2.0 now  sad

Offline

 

#53 2012-10-03 04:12:12

chongyian
Scratcher
Registered: 2012-05-08
Posts: 1000+

Re: EternityX1 Development Topic

XenoK wrote:

chongyian wrote:

Not trying to interfere, but ... OMG! XenoK! you are from singapore too?

Im from the US

http://xenokian.blogspot.sg/? sg?

Offline

 

#54 2012-10-03 07:53:51

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

chongyian wrote:

XenoK wrote:

chongyian wrote:

Not trying to interfere, but ... OMG! XenoK! you are from singapore too?

Im from the US

http://xenokian.blogspot.sg/? sg?

Thats blogger conversion.  For me it shows up as .com

blogger tracks what region you are in, and based on what extensions they have registered, they automatically convert it to that region.  I am from the United States.  The internet is fascinating, isnt it?  Thats what we are trying to harness here at eternity incurakai, the power to amaze.

Last edited by XenoK (2012-10-03 07:59:54)


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#55 2012-10-03 08:05:07

chongyian
Scratcher
Registered: 2012-05-08
Posts: 1000+

Re: EternityX1 Development Topic

oh, that's cool!

Offline

 

#56 2012-10-03 14:16:50

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

P110, could you login to the site, (the login page is currently unaffected by maintenance), and test out the new editing page?  Don't use the link in the admin panel, that's a different file that I'll add later.  go here to test it when you're logged in.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#57 2012-10-03 14:56:14

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

I made some wicked enhancements.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#58 2012-10-03 15:44:58

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

I'm going to make my final adjustments to user_edit.php, and then move on to user_report.php


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#59 2012-10-03 21:08:23

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

Done with user_report.php, it was pretty simple.  The forms look a lot nicer now.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#60 2012-10-03 22:04:48

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

I had some issues with styling the label element for some reason, so we'll have to wrap a div around it with the class labelwrap whenever we make a new form to style it correctly.  Should I keep the background transition for each field?


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#61 2012-10-03 22:17:26

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

If I can get done debugging my code for the current four user_ files, and finish cleaning everything up tonight, I can move onto the user search tomorrow.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#62 2012-10-04 14:26:45

P110
Scratcher
Registered: 2011-04-12
Posts: 500+

Re: EternityX1 Development Topic

arghh, I hate time diff, this sat I should get on loads so we can make quite a bit of progress then, I'll make a sample ip catching code, to show you after  testin user_edit.php


Me live on 2.0 now  sad

Offline

 

#63 2012-10-04 15:55:35

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

kk


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#64 2012-10-04 15:56:32

P110
Scratcher
Registered: 2011-04-12
Posts: 500+

Re: EternityX1 Development Topic

XenoK wrote:

P110, could you login to the site, (the login page is currently unaffected by maintenance), and test out the new editing page?  Don't use the link in the admin panel, that's a different file that I'll add later.  go here to test it when you're logged in.

Works fine! And I like all of the new fields you've added, very professional!!


Me live on 2.0 now  sad

Offline

 

#65 2012-10-04 15:58:50

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

P110 wrote:

XenoK wrote:

P110, could you login to the site, (the login page is currently unaffected by maintenance), and test out the new editing page?  Don't use the link in the admin panel, that's a different file that I'll add later.  go here to test it when you're logged in.

Works fine! And I like all of the new fields you've added, very professional!!

how do you like the tabs?


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#66 2012-10-04 16:08:22

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

the tabs were a bit of work to do.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#67 2012-10-04 20:10:17

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

I'm gonna drop the search.  It's easy to do, but hard to format.  We don't have a whole lot of users, so it won't be necessary to have a search, just maybe not yet.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#68 2012-10-04 20:34:26

trinary
Scratcher
Registered: 2012-01-29
Posts: 1000+

Re: EternityX1 Development Topic

I'm extremely sorry if I am intruding on your thread, but I would like to suggest that you improve the security of your login system.
It's currently very easily broken. I was able to log in as any arbitrary user with an extremely simple piece of SQL injection.


http://trinary.tk/images/signature_.php

Offline

 

#69 2012-10-04 20:36:51

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: EternityX1 Development Topic

trinary wrote:

I'm extremely sorry if I am intruding on your thread, but I would like to suggest that you improve the security of your login system.
It's currently very easily broken. I was able to log in as any arbitrary user with an extremely simple piece of SQL injection.

This can be fixed by simply escaping SQL data.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#70 2012-10-04 20:39:05

trinary
Scratcher
Registered: 2012-01-29
Posts: 1000+

Re: EternityX1 Development Topic

jvvg wrote:

trinary wrote:

I'm extremely sorry if I am intruding on your thread, but I would like to suggest that you improve the security of your login system.
It's currently very easily broken. I was able to log in as any arbitrary user with an extremely simple piece of SQL injection.

This can be fixed by simply escaping SQL data.

Something which they are currently /not/ doing.


http://trinary.tk/images/signature_.php

Offline

 

#71 2012-10-04 20:44:44

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: EternityX1 Development Topic

trinary wrote:

jvvg wrote:

trinary wrote:

I'm extremely sorry if I am intruding on your thread, but I would like to suggest that you improve the security of your login system.
It's currently very easily broken. I was able to log in as any arbitrary user with an extremely simple piece of SQL injection.

This can be fixed by simply escaping SQL data.

Something which they are currently /not/ doing.

It\'s a problem.  tongue
When I took programming at school, one of the units was in security. We learned absolutely nothing there. The whole class was a total waste of my time.  tongue

I learned real programming security through the internet, where I learned that whenever outputting HTML user-submitted data, it needs to be escaped, no matter what context. I also learned that all submitted data used in a SQL query must be escaped.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#72 2012-10-04 21:18:03

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

trinary wrote:

I'm extremely sorry if I am intruding on your thread, but I would like to suggest that you improve the security of your login system.
It's currently very easily broken. I was able to log in as any arbitrary user with an extremely simple piece of SQL injection.

will do.  it's on my list of todos:

> fix WHOIS info
> fix security on login
> go through all current user_ files and debug, and fix spelling mistakes, and digital organization


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#73 2012-10-04 21:36:16

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

P110, I've fixed some of the organization problems I was having with .htaccess.  Also, if the  security on the Eternity Incurakai Login is [messed up], you might want to fix it on treebranch as well, because isn't your login code derived from Tree Branch's?

last edited by me - right now.

Last edited by XenoK (2012-10-04 21:50:01)


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#74 2012-10-04 21:54:33

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

I hate the time diff too   hmm


--

I'll work on improving these files as much as I can before moving onto the admin files for our users section.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#75 2012-10-05 10:22:00

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: EternityX1 Development Topic

Bump


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

Board footer