nope it s not fixed destruction. using rev 6 won t give points if you vote on 350
nope it s not fixed destruction. using rev 6 won t give points if you vote on 350
Using Firefox and Xampp Webserver
This was done again today by another hacker >.<
Heres the Log
462. FcKMaN Entered (Logged In) Login Page 09-10-2008 01:52:50
463. FcKMaN Page Enter/View Vote Info 09-10-2008 01:52:50
He just entered into the Vote Info page and was able to vote thousands of times...
Give full details of the problem,because it seems i do not understand what is the bug here
Will test and fix it(if a bug was found) when full details of the problem are described.
Please include in the details the database for what version are you using .
Probably i will need you for test ... read your PM's in the coming days.
What database and version(ex.Season III 1.04+) of server are you using?
Will re-test that,probably will need someone to test so read your PM's in the coming days.
Last edited by DestructiO; 10-10-08 at 05:00 PM.
I am using 1.04x with a season 3 episode 2 database
i found what the bug is about... just type the link adress and add anything at the end and you will get credits as many times as you want...
e.g. Normal Link: http://www.server,com/vote/user/inde...tte&s=ECN3WAV5
you would type this to get credits:
http://www.server.com/vote/user/inde...N3WAV5anything
each time you hit enter you would get credits as if you were voting... DestructiO please fix this..
Please give a link so i can download this db and test the system on this db.
3 things to say:
- I want to see your Reward Configuration (Make a Screenshot)
- I guess you set up the reward to be only credits
- For now you can fix ( defend ) from this bug by giving the other 2 rewards too.
I'm not 100 % sure this will work cuz i was not able to test it...and i'm not 100% sure that this bug even exists cuz i had more than a 10 tests before i released the system and this kind of thing didn't work.But there for i will re-test again this thing in the coming days,so stay tune if i found something will release a new patch or Revision
The thing is that i dont wanna activate the other 2 rewards.. and i saw the same bug in other servers ( i saw the post in the muweb forum)... and i didnt know about it, so i tried it in my server and it gave me credits each time y typed anything at the end of the link...
lol as always someone trying to save his butt from being flamed. too bad someone already released that trick for the voting points, was fun because only a few new about it. T_T
Ok analyzing completed...
BUG FIXED
Founded where was the problem.
Here is a fix for the adding credits thing.
Test and report if there was any problems.
LINK FOR DOWNLOAD
1st post updated - the fix is attached
When i try to use an invalid link code i get this.Originally Posted by DestructiO
Warning: mssql_query() [function.mssql-query]: message: Invalid column name 'unid'. (severity 16) in C:\xampp\htdocs\mu\Vote\user\votte-kk.php on line 28
Warning: mssql_query() [function.mssql-query]: Query failed in C:\xampp\htdocs\mu\Vote\user\votte-kk.php on line 28
Warning: mssql_num_rows(): supplied argument is not a valid MS SQL-result resource in C:\xampp\htdocs\mu\Vote\user\votte-kk.php on line 29
The player still gets a reward and thisshows up in the logger which means its still unsecure
Try with this Fix
DOWNLOAD
Wow nice man![]()