Message from @johnolithicsoftware

Discord ID: 464476858449395712


2018-07-05 17:00:52 UTC  

it can be fixed as we go

2018-07-05 17:00:59 UTC  

but it must be fixed at some point

2018-07-05 17:01:03 UTC  

Well 42 Membera as we stand now

2018-07-05 17:01:17 UTC  

basically nonexistant in web map

2018-07-05 17:01:38 UTC  

I am doing some testing on it.

2018-07-05 17:02:40 UTC  

Sending an email with the text that was entered into a form field doesn’t necessarily mean that it’s storing the passwords unencrypted, but it isn’t that comforting lol. The important thing is that if I forget my password, the website should not have the capability of telling me what it is, because it should only know my hashed, encrypted password

2018-07-05 17:03:16 UTC  

@johnolithicsoftware get on I found a big problem that allows me to login in under anyones account thanks

2018-07-05 17:03:46 UTC  

It's not unencrypted. The website has SSL

2018-07-05 17:03:55 UTC  

So it's not unencrypted

2018-07-05 17:04:10 UTC  

it gets encrypted when it goes through the website

2018-07-05 17:04:18 UTC  

It allows you to log in under anyone's name?

2018-07-05 17:04:22 UTC  

How?

2018-07-05 17:04:26 UTC  

John hop on vc

2018-07-05 17:04:30 UTC  

TKCC

2018-07-05 17:04:33 UTC  

Welcome to BetaTesting

Basic
<#463848221731717142>
#default

2018-07-05 17:04:36 UTC  

wot

2018-07-05 17:04:42 UTC  

I made that

2018-07-05 17:04:46 UTC  

oh

2018-07-05 17:05:05 UTC  

that is fucking worrying

2018-07-05 17:05:08 UTC  

It for us to post any problems we find.

2018-07-05 17:05:12 UTC  

Okay I'm on VC

2018-07-05 17:08:21 UTC  

Also, as a word of advice, verify someone’s email before reminding them what their username and password are. You don’t have to remind them anyways, but at least make sure they didn’t mistype their email first lol

2018-07-05 17:10:10 UTC  

Yeah I wanted to make it convenient.

2018-07-05 17:17:21 UTC  

The best security procedures are really inconvenient

2018-07-05 17:21:04 UTC  

I’m not trying to be an asshole or anything, I’m not exactly a security expert, this one thing is about all I know. That, and sanitize your PHP inputs lol

2018-07-05 17:23:23 UTC  

sanitize the PHP inputs?

2018-07-05 17:43:20 UTC  

Got a Fashbook.
gm_haifisch

2018-07-05 17:47:14 UTC  

I don’t know very much about sanitizing PHP inputs, except that it’s a pain and it’s important. Basically, if there is input that goes to a PHP page, you need to make sure it doesn’t contain anything that could be used to subvert the intention of the input. People can trick PHP into accepting phony code really easily if it isn’t done. It’s especially common in password fields and such. Generally, everyone hates PHP and tries to avoid it, and yet end up getting wrapped up in it anyways. I’ll post a video related to PHP sanitizing, hopefully it will help.

2018-07-05 17:47:17 UTC  

I added you to the group.

2018-07-05 17:49:05 UTC  

Well, I did do such a thing for some of the PHP, like on the entrance page. Where fake PHP inputs are used and through script replaced by real ones which are not visible to the eye.

2018-07-05 17:51:09 UTC  

https://youtu.be/_jKylhJtPmI
Ah, it’s SQL injection, but yeah it’s related to PHP

2018-07-05 17:52:54 UTC  

It definitely needs a lot of work, but it’s pretty impressive. I know how much work goes into some of that because I’ve done just enough programming to know how tough it is, but not quite enough that I could do as much as has been done with it. If I notice things that need fixing, I’ll try to remember to let you know

2018-07-05 17:54:20 UTC  

A German told me there's no difference between American and German beer.
?

2018-07-05 17:58:09 UTC  

I don't think SQL injection will be much of a problem here.

2018-07-05 17:58:54 UTC  

There's only one place that MySQL is used and that's for the login, and I made that fairly secure against injections through various techniques.

2018-07-05 17:59:11 UTC  

I thought ahead on that issue.

2018-07-05 17:59:53 UTC  

Everything else is encoded and sent to text files.

2018-07-05 18:27:55 UTC  

?membercount

2018-07-05 18:27:55 UTC  

2018-07-05 18:29:33 UTC  

@everyone we have 42 members and 11 in fashbook. If you’ve joined DM me saying so, if you haven’t then join and DM me telling me you just did.

2018-07-05 18:33:27 UTC  

I just added EvilFascistOverlord now