Jump to content


Photo

Okay... So what happened?


  • Please log in to reply
18 replies to this topic

#1 Burnie

Burnie

    Forum Obsessed!

  • Members
  • 4,227 posts

Posted 10 May 2012 - 03:15 PM

So how far back has the forum been restored to?

#2 Rocket

Rocket

    PoliceSpecials.com Guru

  • Power Users+
  • 9,736 posts

Posted 10 May 2012 - 03:22 PM

Restore date appears to be 21st April

#3 Mayday

Mayday

    Forum Convert

  • Members
  • 497 posts

Posted 10 May 2012 - 03:54 PM

My life has been lost with out this site!! I was so Bored :(

#4 TroyTempest

TroyTempest

    Forum Obsessed!

  • Members
  • 12,774 posts

Posted 10 May 2012 - 07:55 PM

So what happened this time? I presume the first assessment wasn't bang on.

#5 Lucas North

Lucas North

    Forum Convert

  • Members
  • 492 posts
  • Karma

Posted 10 May 2012 - 08:24 PM

What the hell have NSI been doing?

Surely it was just a simple case of raising the issue with Invision and letting their team investigate & patch?

#6 goldfgy

goldfgy

    Veteran

  • Power Users+
  • 1,751 posts

Posted 10 May 2012 - 09:07 PM

WELCOME BACK! :new_wave:

#7 Law_Grad

Law_Grad

    Die Hard

  • Members
  • 1,698 posts

Posted 10 May 2012 - 09:39 PM

testing

testing

testingWhy can users still post / use HTML code?



Most BB boards block it outright - to stop any SQL injection.



end test

#8 pmtts

pmtts

    Forum Obsessed!

  • Members
  • 7,459 posts

Posted 10 May 2012 - 09:55 PM

My life has been lost with out this site!! I was so Bored :(


You must lead a lonely one then!

#9 Damsel

Damsel

    Forum Obsessed!

  • Power Users+
  • 6,356 posts

Posted 10 May 2012 - 10:15 PM

Why can users still post / use HTML code?

It wasn't users being able to post using html that was the problem. The software checks for malicious code in posts, IPB had already thought of that.

#10 MRF@1972

MRF@1972

    Settling In

  • Members
  • 211 posts

Posted 10 May 2012 - 10:33 PM

Good to see forum back up and running again

#11 Law_Grad

Law_Grad

    Die Hard

  • Members
  • 1,698 posts

Posted 10 May 2012 - 11:19 PM

It wasn't users being able to post using html that was the problem. The software checks for malicious code in posts, IPB had already thought of that.


Strange that, as that's the whole idea of BB forum, where HTML is substituted for BB code that's specific to the software vendor. A legend if you like, where certain approved tags correspond with certain internal responses. It means that the affect a user has upon the forum is limited to the contents if a posting, it's divorced from the code upon which the whole forum has been created…it's almost a firewall between the user and the back end. As for the idea that IPB has this covered, well, the software vendor recommends that you disable it.

IPS highly recommends you do not enable HTML posting in your community as it is a large security risk. By default, IPS software ships with HTML posting disabled.

Source

#12 DukeDan

DukeDan

    Forum Fixture

  • Members
  • 1,166 posts

Posted 10 May 2012 - 11:22 PM

Is the reason the site went down the same reason described as per Lord Vader's post from 21 April?

Also, I can see that "Facebook" is viewing this thread.

#13 Damsel

Damsel

    Forum Obsessed!

  • Power Users+
  • 6,356 posts

Posted 10 May 2012 - 11:23 PM

Strange that, as that's the whole idea of BB forum, where HTML is substituted for BB code that's specific to the software vendor. A legend if you like, where certain approved tags correspond with certain internal responses. It means that the affect a user has upon the forum is limited to the contents if a posting, it's divorced from the code upon which the whole forum has been created…it's almost a firewall between the user and the back end. As for the idea that IPB has this covered, well, the software vendor recommends that you disable it.Source

Law Grad, I can only post what I was told. If you already knew the answer 1) why bother asking, and 2) why not pose the question to NSI in the correct thread?

#14 Law_Grad

Law_Grad

    Die Hard

  • Members
  • 1,698 posts

Posted 10 May 2012 - 11:38 PM

Law Grad, I can only post what I was told. If you already knew the answer 1) why bother asking, and 2) why not pose the question to NSI in the correct thread?


I did, when it was last posted / last thread about it, that's now lost from the restore. I'm not having a go Damsel, but I have never seen any forum that allows HTML tags to be used by its members…its kind of the purpose of the BB tags having [ brackets as opposed to < as its an internal code that has no universal effect…just the comments box.I was trying to use brevity, and yes for me that's odd :D in the hope that if the forum goes down again, someone might say "someone did mention an anomaly about HTML" As an aside, it's probably why there have been issues in regards editing posts for formatting / broken links / images not displaying correctly etc.Because, and even allowing for any WYSIWYG text editor that pastes unnecessary code…preview and edit suddenly renders a post full of low level HTML code that can get muddled up. And I repeat again, this isn't a hobby horse or argument, but an attempt at flagging up a genuine concern…so please don't allow it to be ignored based upon "it should be posted there" as it sort of misses the issue. All the best, and a round of applause to all those behind the scenes…including yourself for manning twitter Damsel. :P

#15 Lucas North

Lucas North

    Forum Convert

  • Members
  • 492 posts
  • Karma

Posted 10 May 2012 - 11:56 PM

Oh God... they're speaking in Arabic... or Latin... or something, again :new_no:


Posted Image

#16 Sailor

Sailor

    Forum Obsessed!

  • Power Users+
  • 4,224 posts

Posted 11 May 2012 - 05:51 AM

I agree with Law_Grad. HTML posting should be disabled.

#17 Waddle

Waddle

    Forum Obsessed!

  • Power Users+
  • 5,987 posts

Posted 11 May 2012 - 07:08 AM

Well I'm glad to see the forum up and running again, not sure I can get on with Twitter

#18 CmdKeen

CmdKeen

    Forum Obsessed!

  • Power Users+
  • 4,352 posts

Posted 11 May 2012 - 08:50 AM

There is no conceivable reason that HTML tags should lead to SQL injection... After all SQL doesn't contain angle brackets around anything, I could still write by "Little Bobby Tables" post, post title, username any a vulnerability would let it through.

There are valid reasons to ban / allow HTML - especially given the propensity for people in the News section to copy & paste without using the preview button and generate monstrosities.

#19 cyswork

cyswork

    Forum Obsessed!

  • Power Users+
  • 4,070 posts

Posted 12 May 2012 - 10:32 AM

Oh I was worried! haha!




0 user(s) are browsing this forum

0 members, 0 guests, 0 anonymous users