View Full Version : Security Issues
Zoid
March 24, 2007, 05:09
Ok, we really need to get this thing sorted. Locutus has apparently fixed it, but I'm being a bit paranoid here. So to test it I propose that each team posts something in their private forum, then we can see if it shows up in the "new posts" search.
Better safe than sorry, right? ;)
Locutus
March 24, 2007, 05:30
You're welcome to try of course, but I can tap directly into the database and see exactly who can see what forums, and ATM no one can access any of the private forums here. The problem is that (seemingly) random actions to the database (creating new forums, archiving, making people mods or changing their access rights) tends to mess things up and more or less randomly assigns people access privileges they shouldn't have. I'm looking into this to make sure this stops happening in the future, but until then I'll check for it both periodically and whenever we make changes to the database.
Zoid
March 24, 2007, 06:04
Ok, I'll take your word for it. :b:
Btw, we had another glitch here. I can't access this forum (and the other DG forums). Only reason I can answer is that it worked to click the "reply" link in "my threads"... :hmmm:
Locutus
March 24, 2007, 06:39
That's very weird... There is nothing in the database that denies you access, your account looks perfectly normal (as do the forums in question). To be safe I updated your account, do you still have the problem now? If so, do you just not see these forums or do you get a 'no permission' screen?
If you don't see the forums, what happens if you go to them directly by clicking these links:
http://apolyton.net/forums/forumdisplay.php?s=&forumid=304
http://apolyton.net/forums/forumdisplay.php?s=&forumid=259
http://apolyton.net/forums/forumdisplay.php?s=&forumid=288
If you get anything other than a 'no permission' screen, first try rebooting your PC and clearing your browser cache, if you haven't already tried. Test on a different browser if you have several installed. Also, as a test disable any firewall/anti-virus you may have running (or anything else that might interfere with your Internet) -- especially Norton's software is renown for randomly disabling links and denying access to 'suspicious' pages (which most of the time aren't suspicious in any way).
If instead you get a 'no permission' screen, or if none of the above helps, let me know. In that case, would you object to me logging into your account so I can see the problem first-hand?
Zoid
March 24, 2007, 06:57
The links didn't work... And it happened just seconds after I posted this thread. I clicked post thread and then I got the "no permission" screen...
Zoid
March 24, 2007, 07:07
Bugger. :( I cleared my cache and logged out and then back in again. Didn't help... I use Zone Alarm and AntiVir and it hasn't been acting up before so i don't think that's the culprits... I doesn't work in IE either...
Locutus
March 24, 2007, 07:17
Yeah, I've been able to recreate the problem myself now with my own account (my non-admin DL that is), and I've had other reports of this within the last ~hour. It's definitely CivGroup-related, if you were to leave Southern Cross the problem is solved. I'm looking into it...
Locutus
March 24, 2007, 08:22
I seem to have fixed the problem (please let me know), by removing some code Gramphos added this morning but of which I have no idea what it does, so we'll see what happens... :scared:
RobWorham
March 24, 2007, 08:52
Thanks Locutus!!! :b:
Phew!! I was getting withdrawal symptoms for a while there......
Solver
March 24, 2007, 10:25
At any rate, there has to be a measure of trust involved. Clearly, Locutus or myself can access the database directly to see anything that is being said in private forums, but you guys will have to trust us not to :).
Keygen
March 24, 2007, 11:02
There's no question on your integrity, at list regarding me :b:
Rhothaerill
March 24, 2007, 11:30
Most demogames ARE about trust since they were run by PBEM where a whole host of things could be done to cheat if one was so inclined. This game will be less of an issue since you can't restart a result you don't like, but you still trust your opponents not to do something untoward with the game.
Trusting the admins to conduct themselves honestly is just another aspect of the game. Unless you do something untoward then I think most everyone will trust you. :)
proviisori
March 24, 2007, 12:28
:b:
Zoid
March 24, 2007, 14:15
Now it works. Tx Locutus :) :b:
Nugog
March 24, 2007, 15:06
Originally posted by Solver
but you guys will have to trust us not to :).
You won't find me questioning your integrity!
MrWhereItsAt
March 24, 2007, 15:17
Originally posted by Solver
Clearly, Locutus or myself can access the database directly
Clearly, your avatar has never been more appropriate. :scared:
FWIW I can't see any posts from the private forums, but then Loc fixed it that way on my account first up.
FeMme
March 24, 2007, 16:20
We trust you! :b:
vBulletin® v3.8.2, Copyright ©2000-2010, Jelsoft Enterprises Ltd.