so if a mod makes himself look retarded...

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • nofx
    Too lazy to set a custom title
    • Nov 2002
    • 16826

    #1

    so if a mod makes himself look retarded...

    they just close the thread?

    lol, interesting.

    http://www.gfy.com/showthread.php?t=678875

    Often times I wonder why
    There's love and hate, theres live or die.
    When sickness comes I must decide:
    When feelings go, theres suicide.
  • Jace
    FBOP Class Of 2013
    • Jan 2004
    • 35562

    #2
    yeah, i wish TD would expand on what exploits could be done with that youtube addition to the bbcode

    i don't see how it is possible though

    Comment

    • Tuga
      Confirmed User
      • Nov 2002
      • 7678

      #3
      Originally posted by Jace
      yeah, i wish TD would expand on what exploits could be done with that youtube addition to the bbcode

      i don't see how it is possible though
      My 100k users surfer board is now vulnerable, I would love to know that too

      Go Fuck Yourself!
      ICQ 101411627

      Comment

      • Jace
        FBOP Class Of 2013
        • Jan 2004
        • 35562

        #4
        Originally posted by Tuga
        My 100k users surfer board is now vulnerable, I would love to know that too
        yup, me too, I don't have a crazy board with tons of members, but I have a buddy that is going to install that on his board, and if there is a vunerability, I would like to know about it
        Last edited by Jace; 11-19-2006, 03:51 PM.

        Comment

        • nofx
          Too lazy to set a custom title
          • Nov 2002
          • 16826

          #5
          Originally posted by Jace
          yeah, i wish TD would expand on what exploits could be done with that youtube addition to the bbcode
          I doubt we will ever see that

          Often times I wonder why
          There's love and hate, theres live or die.
          When sickness comes I must decide:
          When feelings go, theres suicide.

          Comment

          • minusonebit
            So Fucking Banned
            • Feb 2006
            • 7391

            #6
            I bet TD has his finger on the ban button... trying to restrain himself...

            Comment

            • TexasDreams
              former Miserable Admin :)
              • Oct 2003
              • 4700

              #7
              Originally posted by nofx
              they just close the thread?

              lol, interesting.

              http://www.gfy.com/showthread.php?t=678875
              When I see a request that is retarded, yes.
              ICQ: 168-914-369 >>> sysop [at] TexasDreams [dot] com

              Comment

              • biftek
                So Fucking Banned
                • Jan 2005
                • 1030

                #8
                well i haven't seen any exploits for that bbcode , but i have read about some bogus youtube clips that infect the viewer with zango
                http://www.spywareremovalnews.com/ne...icle-1102.html

                Comment

                • Jace
                  FBOP Class Of 2013
                  • Jan 2004
                  • 35562

                  #9
                  Originally posted by minusonebit
                  I bet TD has his finger on the ban button... trying to restrain himself...
                  with what reason?

                  Comment

                  • crocop
                    Confirmed User
                    • Oct 2006
                    • 205

                    #10
                    i dont see the problem with that code

                    Comment

                    • fusionx
                      Confirmed User
                      • Nov 2003
                      • 4618

                      #11
                      The only downside to embedding youtube and other vids is when people quote and keep the vid in the quote, and autoplay is turned on, it really fucks up your browsing experience ...

                      or, if multiple people post in the same thread, etc. Imagine 20 vids playing, starting at 1 second intervals

                      Comment

                      • Tuga
                        Confirmed User
                        • Nov 2002
                        • 7678

                        #12
                        Originally posted by fusionx
                        The only downside to embedding youtube and other vids is when people quote and keep the vid in the quote, and autoplay is turned on, it really fucks up your browsing experience ...

                        or, if multiple people post in the same thread, etc. Imagine 20 vids playing, starting at 1 second intervals
                        No video in my board autoplays, what option is that?

                        Go Fuck Yourself!
                        ICQ 101411627

                        Comment

                        • Tuga
                          Confirmed User
                          • Nov 2002
                          • 7678

                          #13
                          Originally posted by TexasDreams
                          When I see a request that is retarded, yes.
                          Oh really? Half the threads in GFY ARE RETARDED and I dont see you closing them.

                          The only retarded thing in that thread is.... well you know what.

                          Go Fuck Yourself!
                          ICQ 101411627

                          Comment

                          • TexasDreams
                            former Miserable Admin :)
                            • Oct 2003
                            • 4700

                            #14
                            Originally posted by biftek
                            well i haven't seen any exploits for that bbcode , but i have read about some bogus youtube clips that infect the viewer with zango
                            http://www.spywareremovalnews.com/ne...icle-1102.html
                            That's actually easier than most might think.
                            ICQ: 168-914-369 >>> sysop [at] TexasDreams [dot] com

                            Comment

                            • DarkJedi
                              No Refunds Issued.
                              • Feb 2001
                              • 28301

                              #15
                              TexasDreams doesn't know shit about running web forums.

                              I don't know why adult.com won't hire a real admin.

                              Comment

                              • Tuga
                                Confirmed User
                                • Nov 2002
                                • 7678

                                #16
                                Originally posted by TexasDreams
                                That's actually easier than most might think.
                                He is talking about FAKE you tube clips and that bbcode wouldnt work with that shit, you really dont have a clue do you? That's not a problem, noone knows everything, but you should really try to learn a little bit instead of acting like a fool. This is a webmaster board you know? Some people here know a few things about the interweb. Learn from them.

                                Go Fuck Yourself!
                                ICQ 101411627

                                Comment

                                • 2HousePlague
                                  CURATOR
                                  • Jul 2004
                                  • 14572

                                  #17
                                  Originally posted by TexasDreams
                                  When I see a request that is retarded, yes.
                                  You can't blame me for being oblivious to security threats - I'm not a security guy. The other stuff is subjective.


                                  2hp
                                  tada!

                                  Comment

                                  • Jace
                                    FBOP Class Of 2013
                                    • Jan 2004
                                    • 35562

                                    #18
                                    Originally posted by fusionx
                                    The only downside to embedding youtube and other vids is when people quote and keep the vid in the quote, and autoplay is turned on, it really fucks up your browsing experience ...

                                    or, if multiple people post in the same thread, etc. Imagine 20 vids playing, starting at 1 second intervals
                                    most youtube videos don't autoplay when they are embedded off the youtube site

                                    same with pornotube...hehe..but you knew that

                                    Comment

                                    • Jace
                                      FBOP Class Of 2013
                                      • Jan 2004
                                      • 35562

                                      #19
                                      Originally posted by 2HousePlague


                                      You can't blame me for being oblivious to security threats - I'm not a security guy. The other stuff is subjective.


                                      2hp
                                      I wish he would explain it more detail, I am genuinely curious as to what would happen in regards to security, I have seen tons of forums that did it, and not one has been hacked or ran into issues

                                      Comment

                                      • Jace
                                        FBOP Class Of 2013
                                        • Jan 2004
                                        • 35562

                                        #20
                                        from vbulletins site:

                                        Are there any security issues with this??
                                        The embeded flash is running off youtube's server and there's no html to embed the code. It's all bb code and you're only posting the end numerical value of the video's url.
                                        even the vbulletin experts say there is no security risk

                                        Comment

                                        • Tuga
                                          Confirmed User
                                          • Nov 2002
                                          • 7678

                                          #21
                                          Originally posted by Jace
                                          even the vbulletin experts say there is no security risk
                                          Someone should block those guys, they're retarded

                                          Go Fuck Yourself!
                                          ICQ 101411627

                                          Comment

                                          • Jace
                                            FBOP Class Of 2013
                                            • Jan 2004
                                            • 35562

                                            #22
                                            Originally posted by Tuga
                                            Someone should block those guys, they're retarded
                                            hahahahaha

                                            Comment

                                            • PMdave
                                              Confirmed User
                                              • Dec 2003
                                              • 1517

                                              #23
                                              uhmmm.... isn't that "youtube installs zango"-story based on the fake Yootube.info movies?

                                              Comment

                                              • nofx
                                                Too lazy to set a custom title
                                                • Nov 2002
                                                • 16826

                                                #24
                                                Originally posted by Tuga
                                                Someone should block those guys, they're retarded
                                                bhahahahhaha

                                                Often times I wonder why
                                                There's love and hate, theres live or die.
                                                When sickness comes I must decide:
                                                When feelings go, theres suicide.

                                                Comment

                                                • Tuga
                                                  Confirmed User
                                                  • Nov 2002
                                                  • 7678

                                                  #25
                                                  Originally posted by PMdave
                                                  uhmmm.... isn't that "youtube installs zango"-story based on the fake Yootube.info movies?
                                                  And how the hell is that related to what we are talking about?

                                                  Go Fuck Yourself!
                                                  ICQ 101411627

                                                  Comment

                                                  • EdgeXXX
                                                    Confirmed User
                                                    • Oct 2005
                                                    • 5816

                                                    #26
                                                    Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                    .
                                                    .
                                                    .
                                                    .

                                                    I have a sig

                                                    Comment

                                                    • 2HousePlague
                                                      CURATOR
                                                      • Jul 2004
                                                      • 14572

                                                      #27
                                                      Originally posted by EdgeXXX
                                                      Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                      Is that possible? How could malicious code survive the flash encryption by Youtube?


                                                      2hp
                                                      tada!

                                                      Comment

                                                      • Tuga
                                                        Confirmed User
                                                        • Nov 2002
                                                        • 7678

                                                        #28
                                                        Originally posted by EdgeXXX
                                                        Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                        Ok now you got me interested, but I would like you to get into more detail about it. They can put a script on a video and host it on youtube? And what kind of stuff can that script do to a site that is just displaying the youtube player? I really would like to know.

                                                        Go Fuck Yourself!
                                                        ICQ 101411627

                                                        Comment

                                                        • stickyfingerz
                                                          Doin fine
                                                          • Oct 2005
                                                          • 24984

                                                          #29
                                                          Originally posted by EdgeXXX
                                                          Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                          I dont think youtube allows videos with action script embedded does it? I know Ive tried it with a simliar site of a pornographic nature and the video was automatically rejected.

                                                          Comment

                                                          • CaptainHowdy
                                                            Too lazy to set a custom title
                                                            • Dec 2004
                                                            • 94034

                                                            #30
                                                            Someone close this thread please...

                                                            Comment

                                                            • Jace
                                                              FBOP Class Of 2013
                                                              • Jan 2004
                                                              • 35562

                                                              #31
                                                              Originally posted by EdgeXXX
                                                              Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                              well, isn't IE7 going to be a mandatory download here soon? nothing active or action gets by IE7 for me so far....any time anything tries to run it stops it and prompts me

                                                              happened with Zango too, Zango tried to install on my computer and IE7 said NOPE!

                                                              Comment

                                                              • KrisKross
                                                                Confirmed User
                                                                • Jan 2006
                                                                • 5025

                                                                #32
                                                                Originally posted by EdgeXXX
                                                                Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                                If what you're suggesting is possible, then YouTube would have been raped to hell and back a long time ago.

                                                                Of course script kiddies have taken notice. Hell, I'm not even a script kiddie and it was one of the first thoughts that crossed my mind when I first came across YouTube.

                                                                Comment

                                                                • madawgz
                                                                  8.8.8.8
                                                                  • Mar 2006
                                                                  • 30509

                                                                  #33
                                                                  maybe have the adult team write a custom script so all we have to do is paste the youtube url, and the script will extract the code and put it on the page automatically
                                                                  TAEMDLRMSKRJIXMRLSMRJ.

                                                                  Comment

                                                                  • minusonebit
                                                                    So Fucking Banned
                                                                    • Feb 2006
                                                                    • 7391

                                                                    #34
                                                                    heh, see sig.

                                                                    Comment

                                                                    • 2HousePlague
                                                                      CURATOR
                                                                      • Jul 2004
                                                                      • 14572

                                                                      #35
                                                                      Originally posted by madawgz
                                                                      maybe have the adult team write a custom script so all we have to do is paste the youtube url, and the script will extract the code and put it on the page automatically
                                                                      Actually, you don't even have to past the whole URL, just the identifier code from the end -- like this



                                                                      2hp
                                                                      tada!

                                                                      Comment

                                                                      • Kimo
                                                                        ...
                                                                        • Jan 2006
                                                                        • 11542

                                                                        #36
                                                                        leave that boi alone
                                                                        ...

                                                                        Comment

                                                                        • fusionx
                                                                          Confirmed User
                                                                          • Nov 2003
                                                                          • 4618

                                                                          #37
                                                                          Originally posted by madawgz
                                                                          maybe have the adult team write a custom script so all we have to do is paste the youtube url, and the script will extract the code and put it on the page automatically
                                                                          yeah.. that's what the bb code mod would do

                                                                          PHP Code:
                                                                          [youtube]http://www.youtube.com/watch?v=aAP_pxMqmr4[/youtube] 
                                                                          
                                                                          we built a media tag that plays vids, audio and flash movies from specific sites.. pretty easy for the users, and secure for us.

                                                                          Comment

                                                                          • Jace
                                                                            FBOP Class Of 2013
                                                                            • Jan 2004
                                                                            • 35562

                                                                            #38
                                                                            Originally posted by fusionx
                                                                            yeah.. that's what the bb code mod would do

                                                                            PHP Code:
                                                                            [youtube]http://www.youtube.com/watch?v=aAP_pxMqmr4[/youtube] 
                                                                            
                                                                            we built a media tag that plays vids, audio and flash movies from specific sites.. pretty easy for the users, and secure for us.
                                                                            actually, the youtube one is even cooler

                                                                            it just does this



                                                                            no url even necessary

                                                                            you can do the same with pornotube, no installs or code rewrites necessary

                                                                            Comment

                                                                            • MaddCaz
                                                                              Confirmed User
                                                                              • Mar 2006
                                                                              • 9483

                                                                              #39
                                                                              Texas said FUCKIT!!!

                                                                              BigCocks.com -
                                                                              MatureWomen.com -
                                                                              Tranny.com -
                                                                              DrunkGirls.com -
                                                                              TeenGirls.com -
                                                                              MonsterCock.com and
                                                                              many more... Click
                                                                              here to see them all!

                                                                              Comment

                                                                              • fusionx
                                                                                Confirmed User
                                                                                • Nov 2003
                                                                                • 4618

                                                                                #40
                                                                                Originally posted by Tuga
                                                                                No video in my board autoplays, what option is that?
                                                                                It's dependent on the player

                                                                                Comment

                                                                                • Bro Media - BANNED FOR LIFE
                                                                                  MOBILE PORN: IMOBILEPORN
                                                                                  • Jan 2004
                                                                                  • 16502

                                                                                  #41
                                                                                  Originally posted by EdgeXXX
                                                                                  Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                                                  you don't know much about how YouTube works do you?

                                                                                  you upload a mpg, avi, or mov file, not a flash file, you cannot put actionscript for flash, in an mpg/avi/mov their servers convert it to a FLV file, not even flash, flv can't have actionscript either, so no, theres is no possible way for someone to cause harm or anything to ones computer by uploading a movie to youtube...

                                                                                  ...plus you think Youtube/Google is stupid enough to let shit like that slide? they got programs that catch that shit, i doubt a big company like google, or hell even the guys who started youtube, being ex paypal programmers would even just "overlook" a security flaw like that...

                                                                                  Comment

                                                                                  • fusionx
                                                                                    Confirmed User
                                                                                    • Nov 2003
                                                                                    • 4618

                                                                                    #42
                                                                                    Originally posted by Jace
                                                                                    actually, the youtube one is even cooler

                                                                                    it just does this



                                                                                    no url even necessary

                                                                                    you can do the same with pornotube, no installs or code rewrites necessary

                                                                                    It's easy to modify it that way.. we allow several media sources with the same tag, so we just tell the user to paste the url supplied by the host.

                                                                                    Comment

                                                                                    • studiocritic
                                                                                      Confirmed User
                                                                                      • Jun 2005
                                                                                      • 2442

                                                                                      #43


                                                                                      thread.. closing..
                                                                                      254342256

                                                                                      Comment

                                                                                      • Masterchief
                                                                                        Confirmed User
                                                                                        • Jun 2006
                                                                                        • 530

                                                                                        #44
                                                                                        Originally posted by EdgeXXX
                                                                                        Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
                                                                                        FYI, there's 2 options that render those attacks completely useless, try looking up on the "allowScriptAccess" and "allowNetworking" tags.

                                                                                        Comment

                                                                                        • studiocritic
                                                                                          Confirmed User
                                                                                          • Jun 2005
                                                                                          • 2442

                                                                                          #45
                                                                                          Originally posted by Masterchief
                                                                                          FYI, there's 2 options that render those attacks completely useless, try looking up on the "allowScriptAccess" and "allowNetworking" tags.
                                                                                          this is correct.. same reason myspace allows it now. those tags render flash harmless.
                                                                                          254342256

                                                                                          Comment

                                                                                          • AsianDivaGirlsWebDude
                                                                                            Purveyor, Fine Asian Porn
                                                                                            • Jul 2004
                                                                                            • 38323

                                                                                            #46
                                                                                            Originally posted by Madrox
                                                                                            you don't know much about how YouTube works do you?

                                                                                            you upload a mpg, avi, or mov file, not a flash file, you cannot put actionscript for flash, in an mpg/avi/mov their servers convert it to a FLV file, not even flash, flv can't have actionscript either, so no, theres is no possible way for someone to cause harm or anything to ones computer by uploading a movie to youtube...

                                                                                            ...plus you think Youtube/Google is stupid enough to let shit like that slide? they got programs that catch that shit, i doubt a big company like google, or hell even the guys who started youtube, being ex paypal programmers would even just "overlook" a security flaw like that...
                                                                                            TD is smarter than Paypal/YouTube/Google. That's why he works for Adult.com...

                                                                                            ADG Webmaster
                                                                                            Asian Diva Girls - Exclusive Photos and Videos



                                                                                            Asian Diva Girls Affiliate Program (50% ccBill Revshare)

                                                                                            Comment

                                                                                            • EdgeXXX
                                                                                              Confirmed User
                                                                                              • Oct 2005
                                                                                              • 5816

                                                                                              #47
                                                                                              Originally posted by 2HousePlague


                                                                                              Is that possible? How could malicious code survive the flash encryption by Youtube?


                                                                                              2hp
                                                                                              Well, the problem is not the code surviving the FLV encryption, the danger is of the malicious code hijacking the encoding subroutine before it even begins.


                                                                                              Originally posted by Tuga
                                                                                              Ok now you got me interested, but I would like you to get into more detail about it. They can put a script on a video and host it on youtube? And what kind of stuff can that script do to a site that is just displaying the youtube player? I really would like to know.

                                                                                              Originally posted by stickyfingerz
                                                                                              I dont think youtube allows videos with action script embedded does it? I know Ive tried it with a simliar site of a pornographic nature and the video was automatically rejected.
                                                                                              The problem is not so much a matter of what exploits are known at this very moment, rather what exploitable weaknesses exist that no one has discovered yet. The transition from all content (swf vids) being stored and accessed through a FMS to this new generation of dynamic-loading external FLVs has come about a much greater rate than was initially anticipated (and the increased demand is pushing up development deadlines and cutting test time prior to release).


                                                                                              Originally posted by Jace
                                                                                              well, isn't IE7 going to be a mandatory download here soon? nothing active or action gets by IE7 for me so far....any time anything tries to run it stops it and prompts me

                                                                                              happened with Zango too, Zango tried to install on my computer and IE7 said NOPE!
                                                                                              True, but unfortunately that is only for now. Once the blackhats have time enough to play with IE7 and find it's potential weaknesses, it will be open season on IE again.

                                                                                              Originally posted by KrisKross
                                                                                              If what you're suggesting is possible, then YouTube would have been raped to hell and back a long time ago.

                                                                                              Of course script kiddies have taken notice. Hell, I'm not even a script kiddie and it was one of the first thoughts that crossed my mind when I first came across YouTube.
                                                                                              That's just it (it's kind of complicated... or at least, difficult to explain), we do know that it is possible, we just don't know how. Fortunately neither do they. Basically, it's a race to see who can figure it out first. At the moment (and for the foreseeable future), everything is fine and secure. What the future holds, however, is anybody's guess.
                                                                                              .
                                                                                              .
                                                                                              .
                                                                                              .

                                                                                              I have a sig

                                                                                              Comment

                                                                                              • EdgeXXX
                                                                                                Confirmed User
                                                                                                • Oct 2005
                                                                                                • 5816

                                                                                                #48
                                                                                                Originally posted by Masterchief
                                                                                                FYI, there's 2 options that render those attacks completely useless, try looking up on the "allowScriptAccess" and "allowNetworking" tags.
                                                                                                This is true. But what happens if someone discovers a way to circumvent or override those method tags? Keep in mind, those very methods were just recently adapted due to a weakness discovered in previous platforms.
                                                                                                .
                                                                                                .
                                                                                                .
                                                                                                .

                                                                                                I have a sig

                                                                                                Comment

                                                                                                • AsianDivaGirlsWebDude
                                                                                                  Purveyor, Fine Asian Porn
                                                                                                  • Jul 2004
                                                                                                  • 38323

                                                                                                  #49
                                                                                                  Good advice - be afraid of the unknown...

                                                                                                  ADG Webmaster
                                                                                                  Asian Diva Girls - Exclusive Photos and Videos



                                                                                                  Asian Diva Girls Affiliate Program (50% ccBill Revshare)

                                                                                                  Comment

                                                                                                  • georgeyw
                                                                                                    58008 53773
                                                                                                    • Jul 2005
                                                                                                    • 9865

                                                                                                    #50
                                                                                                    Originally posted by TexasDreams
                                                                                                    When I see a request that is retarded, yes.
                                                                                                    How is it a vulnerability? It only plays youtube videos.

                                                                                                    I've added it to one of my boards cos it's far better than seeing all those shitty youtube links everywhere
                                                                                                    TripleXPrint on Megan Fox
                                                                                                    "I would STILL suck her pussy until her face caved in. And then blow her up and do it again!"

                                                                                                    Comment

                                                                                                    Working...