This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#26 2010-06-07 17:19:36

RHY3756547
Scratcher
Registered: 2009-08-15
Posts: 1000+

Re: Beta test my upload service

Next you should be able to give stuff unique names, and search through stuff google style!  big_smile

Offline

 

#27 2010-06-07 17:32:59

coolstuff
Community Moderator
Registered: 2008-03-06
Posts: 1000+

Re: Beta test my upload service

Wow, that's really good! Great job!

Btw- I have a mac and it works great - except I can't upload stuff.

Offline

 

#28 2010-06-07 18:09:41

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

coolstuff wrote:

Wow, that's really good! Great job!

Btw- I have a mac and it works great - except I can't upload stuff.

Just as I feared...I guess I really do need to switch hosts then. Does anyone have any suggestions for reliable hosting services?


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#29 2010-06-07 18:11:05

coolstuff
Community Moderator
Registered: 2008-03-06
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

coolstuff wrote:

Wow, that's really good! Great job!

Btw- I have a mac and it works great - except I can't upload stuff.

Just as I feared...I guess I really do need to switch hosts then. Does anyone have any suggestions for reliable hosting services?

000webhost seems to work well - very flexible, no ads, and quite reliable, IMHO. I'd reccomend them.

Offline

 

#30 2010-06-07 18:22:10

RHY3756547
Scratcher
Registered: 2009-08-15
Posts: 1000+

Re: Beta test my upload service

byethost is quite good.

Offline

 

#31 2010-06-07 18:43:00

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

RHY3756547 wrote:

byethost is quite good.

My friend uses ByetHost, but I'm really looking for a place that uses cPanel.
@everyone I'm finally home, and I'm checking out your glitch reports now. Thanks for the feedback!

Last edited by fullmoon (2010-06-07 18:43:12)


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#32 2010-06-07 18:44:20

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

Okay, I've confirmed the strange Firefox flash glitch...


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#33 2010-06-07 18:45:36

coolstuff
Community Moderator
Registered: 2008-03-06
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

RHY3756547 wrote:

byethost is quite good.

My friend uses ByetHost, but I'm really looking for a place that uses cPanel.
@everyone I'm finally home, and I'm checking out your glitch reports now. Thanks for the feedback!

000webhost uses cPanel. It's quite flexible, too, with quite a bit of support for pretty much every web programming language available - all for free!

Also, it may not be the host that's not allowing me to upload. I just click the "Upload" link and nothing happens, so it may be a problem with your scripting  smile

Offline

 

#34 2010-06-07 18:59:45

adriangl
Scratcher
Registered: 2007-07-02
Posts: 1000+

Re: Beta test my upload service

Wow, really great? May I ask how you made?


Scratchin' since 2007

Offline

 

#35 2010-06-07 19:00:52

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

...and the HTML uploader glitch!  smile

what-the wrote:

fullmoon wrote:

Oh, are you using the HTML (non Flash) uploader? I haven't tried that in a while.

I am using firefox and I see nothing when I use the Flash uploader and I have flash.

Thanks so much for pointing that out! It's fixed now.

Last edited by fullmoon (2010-06-07 19:09:56)


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#36 2010-06-07 19:05:14

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

coolstuff wrote:

fullmoon wrote:

RHY3756547 wrote:

byethost is quite good.

My friend uses ByetHost, but I'm really looking for a place that uses cPanel.
@everyone I'm finally home, and I'm checking out your glitch reports now. Thanks for the feedback!

000webhost uses cPanel. It's quite flexible, too, with quite a bit of support for pretty much every web programming language available - all for free!

Also, it may not be the host that's not allowing me to upload. I just click the "Upload" link and nothing happens, so it may be a problem with your scripting  smile

Oh, so you can load the page? I've tried on various macs and they all seem to be reluctant to open anything from this domain at all. Well, the good news is then that it's just a problem with getting my flash file to load properly. It, er, worked great in Chrome. May I ask what browser you're using?


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#37 2010-06-07 19:09:33

coolstuff
Community Moderator
Registered: 2008-03-06
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

coolstuff wrote:

fullmoon wrote:


My friend uses ByetHost, but I'm really looking for a place that uses cPanel.
@everyone I'm finally home, and I'm checking out your glitch reports now. Thanks for the feedback!

000webhost uses cPanel. It's quite flexible, too, with quite a bit of support for pretty much every web programming language available - all for free!

Also, it may not be the host that's not allowing me to upload. I just click the "Upload" link and nothing happens, so it may be a problem with your scripting  smile

Oh, so you can load the page? I've tried on various macs and they all seem to be reluctant to open anything from this domain at all. Well, the good news is then that it's just a problem with getting my flash file to load properly. It, er, worked great in Chrome. May I ask what browser you're using?

Apple Safari 4.0.5 on Mac OS X v10.6.3

Offline

 

#38 2010-06-07 19:12:00

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

coolstuff wrote:

Apple Safari 4.0.5 on Mac OS X v10.6.3

Hmmm...brand spanking new operating system and browser  neutral  . I'm using the SWFobject library in my Javascript code, which is supposed to be the "standard" but apparently doesn't work too well sometimes. I'll have to look into that.

Fixed another glitch you guys keyed me into. Thanks so much!

Last edited by fullmoon (2010-06-07 19:20:51)


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#39 2010-06-07 19:36:45

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

Just pathetic in IE...it tells me there's an error on a line of code that does not exist.
http://www.scratch.mit.edu/ext/youtube/?v=vTTzwJsHpU8

I think Internet Explorer 7 should be banned.


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#40 2010-06-07 19:41:09

coolstuff
Community Moderator
Registered: 2008-03-06
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

Just pathetic in IE...it tells me there's an error on a line of code that does not exist.
http://www.scratch.mit.edu/ext/youtube/?v=vTTzwJsHpU8

I think Internet Explorer 7 should be banned.

I absolutely despise Internet Explorer. It ignores all standards, yet it is the most popular browser on the 'net, making programming for the internet a real pain.

Offline

 

#41 2010-06-07 20:49:59

fg123
Scratcher
Registered: 2008-11-13
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

Everyone who is having trouble uploading: what is your browser and OS? I have only extensively tested it on Chrome on Vista, and occasionally I can't even access the page from  my school's macs.

Safari on windows.


Hai.

Offline

 

#42 2010-06-07 23:18:49

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

I think I'm going to move this service to its own domain at some point in the future. Unfortunately I'll have to do some creative domain hacking (not as evil as it sounds  wink  ) to get a cheap domain that's not already registered by some Indian corporation. My options for short, Stuff-based domains are pretty limited. I'm thinking:

s.torage.net

or

st.uffit.net

or

s.tuff.it

For some reason (s).tuff.net redirects to Suicide.org  neutral

Last edited by fullmoon (2010-06-07 23:21:46)


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#43 2010-06-08 07:35:43

coolstuff
Community Moderator
Registered: 2008-03-06
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

I think I'm going to move this service to its own domain at some point in the future. Unfortunately I'll have to do some creative domain hacking (not as evil as it sounds  wink  ) to get a cheap domain that's not already registered by some Indian corporation. My options for short, Stuff-based domains are pretty limited. I'm thinking:

s.torage.net

or

st.uffit.net

or

s.tuff.it

For some reason (s).tuff.net redirects to Suicide.org  neutral

big_smile  You can already get some really cheap domains for as little as $10 a year; that's what I do. It's cheap and easy!

Offline

 

#44 2010-06-08 12:22:11

dav09
Scratcher
Registered: 2009-03-25
Posts: 1000+

Re: Beta test my upload service

i know blacknight.com is very cheap. how did u make this?

Last edited by dav09 (2010-06-08 12:29:47)

Offline

 

#45 2010-06-08 19:33:52

archmage
Scratcher
Registered: 2007-05-18
Posts: 1000+

Re: Beta test my upload service

You need to secure your site from code injections better. Using the firefox tool "tamper data" I was able to use the code injection user:’ or 1=1– to log into a user that doesn't exist. To do this go to the login page, then turn on tamper data, type in anything then press enter, then when the tamper window pops up put the password as blank and the user as user:’ or 1=1– .

You wanted some bug reports so there you go.


Hi, I am Archmage coder extraordinaire. I do Scratch,pascal,java,php,html, AS2 and AS3. Leave me a message if you want coding advice. Also check out my personal website, lots of good stuff about web development, Flash, and Scratch (v1 and v2) !

Offline

 

#46 2010-06-08 19:46:56

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

archmage wrote:

You need to secure your site from code injections better. Using the firefox tool "tamper data" I was able to use the code injection user:’ or 1=1– to log into a user that doesn't exist. To do this go to the login page, then turn on tamper data, type in anything then press enter, then when the tamper window pops up put the password as blank and the user as user:’ or 1=1– .

You wanted some bug reports so there you go.

Always a critic  wink

This isn't really a security hole. There's really no advantage to be gained by injecting a username because that user will either not be validated, or will have access to...nothing. In fact, I seriously doubt that this injection really did anything, since I never refer to "user" in my code.


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#47 2010-06-08 19:50:43

fullmoon
Retired Community Moderator
Registered: 2007-06-04
Posts: 1000+

Re: Beta test my upload service

archmage wrote:

You need to secure your site from code injections better. Using the firefox tool "tamper data" I was able to use the code injection user:’ or 1=1– to log into a user that doesn't exist. To do this go to the login page, then turn on tamper data, type in anything then press enter, then when the tamper window pops up put the password as blank and the user as user:’ or 1=1– .

You wanted some bug reports so there you go.

Although I'd be interested to know where you made the injection. I've tried various "drop tables" style SQL injections without any success so I don't really know what page you're talking about.


http://i302.photobucket.com/albums/nn100/fullmoon32/wow.jpg

Offline

 

#48 2010-06-08 19:59:22

fg123
Scratcher
Registered: 2008-11-13
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

RHY3756547 wrote:

byethost is quite good.

My friend uses ByetHost, but I'm really looking for a place that uses cPanel.
@everyone I'm finally home, and I'm checking out your glitch reports now. Thanks for the feedback!

000webhost, or freehostingcloud.  smile


Hai.

Offline

 

#49 2010-06-08 20:12:39

archmage
Scratcher
Registered: 2007-05-18
Posts: 1000+

Re: Beta test my upload service

fullmoon wrote:

archmage wrote:

You need to secure your site from code injections better. Using the firefox tool "tamper data" I was able to use the code injection user:’ or 1=1– to log into a user that doesn't exist. To do this go to the login page, then turn on tamper data, type in anything then press enter, then when the tamper window pops up put the password as blank and the user as user:’ or 1=1– .

You wanted some bug reports so there you go.

Always a critic  wink

This isn't really a security hole. There's really no advantage to be gained by injecting a username because that user will either not be validated, or will have access to...nothing. In fact, I seriously doubt that this injection really did anything, since I never refer to "user" in my code.

Its a code injection, its not supposed to be there even if it seems harmless. I couldn't access anything but there is a possibility that some better programmers would be able to do some damage. I know you put some security on it ( i tried to display your tables, no dice) but hackers can be sneaky. The blank user had access to its settings and could upload things.

The "user" part of the injection isn't important, its the or 1=1 part that does something. I don't think the word user in that injection does anything.

The injection was made on the login page, lemmie brake it down for you:

1. have firefox and tamper data installed
2. go to login page and enter anything in the text field
3. Press the start tamper button on tamper data
4. enter your fake pass
5. When the tamper data page pops up replace your fake pass with a blank and replace user with user:’ or 1=1–
6. Ok and submit the changes
7. You are logged in

I think you should remove non alpha-numeric characters where ever possible for things like usernames. That should make that injection impossible.

Last edited by archmage (2010-06-08 20:15:52)


Hi, I am Archmage coder extraordinaire. I do Scratch,pascal,java,php,html, AS2 and AS3. Leave me a message if you want coding advice. Also check out my personal website, lots of good stuff about web development, Flash, and Scratch (v1 and v2) !

Offline

 

#50 2010-06-08 20:32:10

Greenboi
Scratcher
Registered: 2010-01-30
Posts: 1000+

Re: Beta test my upload service

Nice site I gotta say.  big_smile

Offline

 

Board footer