• My browsergame, Spittor
    529 replies, posted
How are you entered onto the high score list? Barring the people who obviously cheated (craploads of money/levels) people with only $50,000 cash/networth are on there. I have a higher net worth ($252,000), but low cash ($10) Is it based off net worth or cash? Or is it just broken in general. Edit: Is the site down?
yeah
how the hell are these guys cheating also it's down D:
[quote]Forbidden You don't have permission to access / on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request. Apache/2 Server at [url]www.spittor.com[/url] Port 80[/quote] Isn't that the aftermath of a DDOS?
Aww maaaaan. [editline]04:07PM[/editline] [QUOTE=Ssandman;18667265]how the hell are these guys cheating also it's down D:[/QUOTE] I didn't cheat to gain my semi-vast fortune. I managed to win an auction for 5000 gold bars for a few dollars, and by selling them, I got enough money to buy several gold bar factories.
[QUOTE=SamPerson123;18667279]Aww maaaaan. [editline]04:07PM[/editline] I didn't cheat to gain my semi-vast fortune. I managed to win an auction for 5000 gold bars for a few dollars, and by selling them, I got enough money to buy several gold bar factories.[/QUOTE] I took advantage of idiots who sell those filthy rich cards for no money.
Do you think it's down because he's fixing the fractions of items bug?
[QUOTE=Spittor.com]BBL.[/QUOTE] Sounds like he's updating the game.
It's just down because I want to be sure there's no security flaws. Don't worry though, there won't be a reset this time. Could take a while before I get it back up though. Thanks to the many people who have already sent me emails about bugs and suggestions. You'll be rewarded when the game launches for real.
[QUOTE=panasonic;18666847]I don't see what you mean Swebonny, passwords are stored as a hash anyway. And inputs are sanitized properly. I've already taken out the PM system since that had a flaw if that's what you mean. If you know about any other security flaws can you please report it to me then?[/QUOTE] I don't know if it is the PM thing, but a user was able to get other users passwords, hence Mythic and Garyon are banned. [editline]10:19PM[/editline] because the "hacker" used their accounts here to troll
[QUOTE=Swebonny;18667509]I don't know if it is the PM thing, but a user was able to get other users passwords, hence Mythic and Garyon are banned. [editline]10:19PM[/editline] because the "hacker" used their accounts here to troll[/QUOTE] Where did Vladh go anyway? He's not in the IRC anymore.
its not that hard [editline]09:23PM[/editline] for vladh anyways [editline]09:27PM[/editline] vladh was never in irc though
Well I'm back from changing all my other passwords to something different, just to be sure. Anything and everything i care about has had it's password changed for safety. Phew. And, I used a old e-mail address to sign up to the game, with a different accountname to what I use for everything else. I should be fine, but I'm paranoid :(
Grr, I can't see if I won my gold bars or not. D:
I've had a good chat with Vlad, he helped me locate the errors. Yeah, I left some pretty dumb ones in there. Ouch. It'll be thorougly tested though next time it goes online.
[QUOTE=panasonic;18668282]I've had a good chat with Vlad, he helped me locate the errors. Yeah, I left some pretty dumb ones in there. Ouch. It'll be thorougly tested though next time it goes online.[/QUOTE] Any chance you know whos passwords have been taken, and who took them? I'm really shitting it here!
[QUOTE=ChaosUnleash;18668355]Any chance you know whos passwords have been taken, and who took them? I'm really shitting it here![/QUOTE] vladh: not yours
Oh phew. I'll stop worrying then.
hey my bro wants to know if he can talk to vlad in any way grayron m8 can u arrange that [editline]10:10PM[/editline] eg steam
theyre talking on irc righ tnow
If you want to talk to Vladh: [url]http://vladh.net/contact[/url] [url]http://steamcommunity.com/id/shesonly18[/url]
Any guess on when the game will be back up?
Give it about half an hour more.
[QUOTE=panasonic;18666847]I don't see what you mean Swebonny, passwords are stored as a hash anyway. And inputs are sanitized properly. I've already taken out the PM system since that had a flaw if that's what you mean. If you know about any other security flaws can you please report it to me then?[/QUOTE] The thing about hashes is that if you can get access to the hash, you can bruteforce it quite easily if the password is 6 chars or less. So optimally you should do two things: 1, make sure the hash can never be exposed through injection or any other technique, and 2, use a password validator for registration that makes sure the password is at least 8 chars and contains more than just lowercase letters.
Bbl.
[QUOTE=shill le 2nd;18670649]least 8 chars and contains more than just lowercase letters.[/QUOTE] For important things, I personally use a ~20 character long thing with random letters and symbols. It works quite nicely (also it helped me practice memorization :D)
Holy shit what's taking him so long?
[QUOTE=billyman;18672730]Holy shit what's taking him so long?[/QUOTE] He did say he was going to test it more.
[QUOTE=Newbienice99;18672753]He did say he was going to test it more.[/QUOTE] I sure hope he doesn't delete my whole account. Well, He told me in a pm that he was keeping the accounts, and removing gold factories, adding new factories, and items.
I do hope he gets rid of the accounts with excessive amounts of money. Otherwise, what's the point of a high score list at all.
Sorry, you need to Log In to post a reply to this thread.