Here I am

HTML and UBB Code

Attention: TDR Forum Junkies
To the point: Click this link and check out the Front Page News story(ies) where we are tracking the introduction of the 2025 Ram HD trucks.

Thanks, TDR Staff

Call waiting for PC

TSB's

Status
Not open for further replies.
It wasn't the pointing out the security problem that was immature. Its the sarcastic "What about java applets? Are they acceptable for a discussion forum?" comments...


[This message has been edited by ken (edited 12-21-2000). ]
 
Mike,

Repost your comments, please. I thought I hit the quote link but I hit edit by mistake. UBB allows admins to edit ANY post and it doesn't warn you. Did not mean to overwrite your comment.

-Ken
 
Ken,
I am astonished that you have violated the guidelines of this forum by attacking my character. Perhaps the wording I used was not the best in the applet scenario. Apparently, you have misinterpreted my intentions of the posts in this thread. I felt as though it would be good if the filter you created were tested. I did that. The filter failed. You then stated that the filter was fixed. I tested again. My test showed that the filter was still incomplete. As I continued to think of ways that someone could harm the well being of this site, I decided to see if your filter would catch applets. Again the filter failed. You must realize until this subject was brought up I had NO experience with Java scripts or applets. I have a total of six hours involved in learning how to do what I have done in this thread. I have spent this time in an effort to help you test your filter so that I would know everyone's visits to this site would be safe. Nothing here is malicious. However, imagine what someone could do if they actually knew what they were doing. Everyone here is giving you thanks for fixing this security issue yet it is not fixed as you say it is. So far all I have gotten out of this thread is a lot of grief, no gratitude, and have been personally attacked by your comments. Why is that? I am trying hard to make this place better and all you can do is insult me.
I can understand that in programming it is hard to always find every possible weak point of that program. Had you made your email address available to the public, I could have made these tests, removed the posts, and let you know the results of my tests. However that is not the case. For whatever reason, you have chosen to conceal your address. Therefore, how was anyway to let you know that the filter is in need of attention other than making a post and proving that it was possible to make a post that could me malicious?
As you can see by my response to Jff24Gordn, I do not want to keep this annoying banner on this thread. I thought that you could of at least acknowledged that the filter was not fixed yet. I will be more than happy to remove anything from this thread. If you accept that you have more work to do, feel free to take it down yourself.

I think you owe me an apology.
 
Bryan,

I had no problems with the postings showing the filters weren't working. I was thankful for it.

The sarcastic jibe about whether java applets were acceptable discussion, however, was not very adult. We all know that applications are not "discussion. " How else would you expect me to read what you said other than as sarcasm? If you're going to try to see if the code I wrote works, do so and I'd gladly do what I can to fix the filter, but please keep the sarcasm out of it.

As to the reason why I don't have my email address lists, you can email me by using the webmaster@turbodieselregister.com address plastered over several areas of the site. I do not list my personal email address in UBB because UBB is insecure and allows email addresses to be harvested by "spambots", programs that spider their way through web sites to gather email addresses to put on junk email lists. As admin of a very busy site, I already get more email than I can deal with (over 84,000 in the year 2000 alone). Any user who makes their email address available on any UBB sets themselves up to get more junk email. According to the server logs, 4 spiders (Email Siphon, Cherry Picker, EmailWolf and Web Bandit) have hit the site since December 1st and retrieved a great many of the UBB pages, meaning you'll get more spam.

-Ken


[This message has been edited by ken (edited 12-22-2000). ]
 
Do you accept that you have more work to do? I did not intend sarcasm, I was amazed I could get the app to work and probably worded the post out of excitement. I am sorry if you took it as sarcasm, I didn't mean it that way. Should I accept this is as your way of apologizing? I have a lot of time checking your work and would appreciate it if you show me a little respect.
 
We appreciate member's support in locating and providing fixes to any possible security breaches in our web site. We feel Ken, our webmaster, works very hard to keep on top of these types of things. We also feel you, as the users, can and do help in pointing out where additional work is needed. A sincere thank you is extended to each of you.

For the good of the site, however, I respectfully ask that this banner is removed and that all feedback which is provided - whether it is to the webmaster from a member or whether it is from the webmaster to a member be kept professional and fun.

Thank you for your support with this request.

Robin W. Patton
Turbo Diesel Register
 
I'm not sure who deleted the banner, but thank you. And again, thank you for all of your help in making this site perform better each day.

Robin
 
this post is intended to show you that the codes aren't working. . as of 8:26am pst

Merry Christmas

it [the reply ] also changes what was typed. . I put in the > signs on the original reply post[pre edit]

[This message has been edited by willyslover (edited 12-22-2000). ]
 
Robin & Ken... first off I do have to say thanks for your help in trying to make the TDR a Safer place to be. But IMO, I do have to say that I agree with some of the points that Bryan is trying to make. Everyone needs to hear him out. Why not make a thread just for testing the filters? See what people can do (in a safe mannor... using common sense, such as the banner)to defeat them. . so that you guys are aware of the back doors. In the long run all it can do is help you guys out. Of course I am not trying to question your authority or make you do more work... just giving a quick opinion of how we all can pitch in and make the TDR a fun and safe place to be

Just throw'n in my $. 02

Thanks

Kev

[This message has been edited by K_Arts (edited 12-22-2000). ]
 
Just an idea, for what it's worth. I have 40 years in the computer industry. As a person who has done some programming, I am always glad to have constructive help in debugging anything.

There is help and there is help. To forcibly grab someones nose and rub it in the problem, publicly servers two purposes. First it demonstrates that you know what you are talking about. Second it is degrading to the person that you are bashing.

I would submit that an e-Mail can tell the website administrator of any problem that might be uncovered. If one really wanted to be helpful examples of the offending code could be submitted in the e-Mail. I think you all get the message.

We are here because of our common interest in Diesel trucks. It is possible to help eachother and not be degrading.

"Because you can do a thing, it does not mean that you should do a thing. "

Sorry if this makes anyone unhappy. Just my $. 02
 
No problem here. If it is necessary to post to the board to determine that your suspicions are correct and it is non destructive, then so be it. Would there be a problem with then removing the post, and sending an e-Mail with the code to the admin. What point does leaving it there serve. If documentation is necessary, then a post could be written saying that a problem has been discovered and admin was notified that would not create anybody a problem.

Didn't post my message as a result of your post. The rest of it seemed to be getting heavy and served no purpose.
 
Adillo. . I agree 100% with what you are saying, and I am not trying to imply that people should post destructive scripts at all. Just something very unharmful... as the banner that was on this page. It was simple, to the point and should be fixed.

I don't want to degrade anybody at all. Just make people aware of how dangerous even the simplest code can be and IMO, we can't send an e-mail to the TDR Admin about something unless we know that it is a potential problem on this board. So it would be nice, if someone ran across something, if we could have a place to test it, then delete it. Then submit it to the Admin as a possible problem to be fixed. Does that Make sense?

Kev

[This message has been edited by K_Arts (edited 12-22-2000). ]
 
Something is broke again. Everytime a person trys to use a HTML tag when you post it or edit it the first "" is knocked off, therefore the HTML will not work.

Anyword on the problem, or the fix? Information is a valuable tool!

Also last week Ken you said there would be an announcement on the forum software change? Well its been a week and still no word?

My official vote is for VBulletin!!!

NOT, I repeat NOT DCForums!!!!!!!!!

------------------
font color=blue>
  • Eric D. Howard - #ad
    - Outlaw BOMB'er! - #ad
    - TDR Member since April 8th, 2000, Rancho 9000 shocks
  • 2001 Dodge Ram 2500 HD 4x4 SLT Auto Reg cab Cummins Turbo Diesel 4. 10 gear ratio LT265/75R/16 tires
  • Patriot Blue Pearl Coat, Agate interior, Leather seats EVERY option, Silencer Ring AWOL, Trans Go Shift Kit
  • JRE 4" Exhaust, "Hot" PowerEdge, Autometer UltraLite Gauges (EGT, Custom Boost, transmission temp), K&N Airfilter
font>

[This message has been edited by KatDiesel (edited 12-23-2000). ]
 
Last edited by a moderator:
Kpayne, Thanks for posting the info on email, UBB and spambots. Being rather computer illiterate I had no idea spambots even existed and could get to my email address if my email address was made availible to other users in my profile. Therefore I have changed my profile, for I've been a victom of the spambots on several occasions.

As a suggestion, should a warning be included on the profile page regarding the hazards of making your email address availible to others on the TDR?

I'd rather not 'hide' my email address to the TDR members but feel a need to do so in the interest of my PC's security.

Question, If my email address is availible to only TDR admin and moderators will the spambots be able to find my email address?
 
KatDiesel,

You're going to have to practice a little patience. I know its tough waiting 3 days for HTML, especially since most people are busy celebrating the birth of Christ this weekend. I'm enjoying the holiday with family, not programming Perl. I'll be back in town on Thursday.

Ken


[This message has been edited by ken (edited 12-25-2000). ]
 
I quote:

"Been at least 3 days now"

Written on the 25th. That means I was expected to work the holiday weekend so I could acknowledge a minor problem.

Patience... ... . #ad


As to the spambot issue, this information has been widely available in FAQs specific to such issues for years. I would strongly encourage users to educate themselves about the Internet and search out the FAQs.

As to the question, only publically available email addresses can be taken by spambots.

Ken


[This message has been edited by ken (edited 12-26-2000). ]
 
Originally posted by ken:
You're going to have to practice a little patience. I know its tough waiting 3 days for HTML, especially since most people are busy celebrating the birth of Christ this weekend. I'm enjoying the holiday with family, not programming Perl. I'll be back in town on Thursday.

I have plenty of patience. Doing what I do for a living I am subject to alot of things beyond my control but yet I still have to keep things moving to the best of my abilities, so yes I know what patience is. However, I do not have patience for replies that are saracastic or "smart allec" like. I merely asked a simple question if you were aware of the problem. A forum of this size a problem should be noted within 3 days regardless what day of the year it is. I am happy you are celebrating the holidays but they do make laptops, and you godd have at least acknowledged the problem exhisted rather then trying to be smart. I for one am sick and tired of the way you talk down to the members of this forum. My post above was a simple question of whether or not it was a noted problem. There was no sarcasim in my post (believe me I have been holding back).
I figure 3 days is plenty of time to say "Yes, there is a problem I will address it when I get back", and the problem would have been solved. But no you had to use you Holier then thou attitude like you always do. So therefore I have no patience left.

As I have said before a little information goes along way.
 
Status
Not open for further replies.
Back
Top