Zero Identity
Username: Password:
[Forgot Password?] [Not Registered?]

ZI Store Updates

Zi Store

Online Users

Registered Users: 2016
Latest Registration: yhamrodne
Online Users: 9
(0 Members, 9 Guests)

Poll

What should be done first on the ZI overhaul?
Find more staff (45%) [10 Votes]
Fix all bugs (36%) [8 Votes]
Make new features (not challenges) (9%) [2 Votes]
Get more content (challenges etc) (9%) [2 Votes]

[Poll Archive]

Kr0wKr0w

Avatar

Last Login:
2012-01-20
Joined:
December 11 2009 01:08
Experience:
2
(16 day(s) ago)
The crashed tables for registration and other stuff is easy to fix (using the Mysql command "REPAIR TABLE").
ttyler333ttyler333
php coder
Avatar

Last Login:
0000-00-00
Joined:
May 09 2008 01:45
Experience:
1095.2
(18 day(s) ago)
according to a friend the registration doesn't work.
hack4uhack4u
ZI Owner
Avatar

Last Login:
0000-00-00
Joined:
March 30 2008 22:30
Experience:
20492
(19 day(s) ago)
Please do keep a list of all the bugs. They might eventually get fixed.. lol.
Hunter XHunter X

Avatar

Last Login:
0000-00-00
Joined:
September 25 2010 15:44
Experience:
0
(01 month(s) ago)
What we could do is start compling a list of bugs on the Tasks page, so if and when development resumes the developers know what needs doing.
Kr0wKr0w

Avatar

Last Login:
2012-01-20
Joined:
December 11 2009 01:08
Experience:
2
(02 month(s) ago)
Kewl, the domain renewed another year. :) Any other future plans?
Hunter XHunter X

Avatar

Last Login:
0000-00-00
Joined:
September 25 2010 15:44
Experience:
0
(02 month(s) ago)
I've got no idea. I'll send off an email to one of the admins in a moment to check, since I've been meaning to contact them anyway.
Hunter XHunter X

Avatar

Last Login:
0000-00-00
Joined:
September 25 2010 15:44
Experience:
0
(02 month(s) ago)
There seems to be ~10 guests on most days, but I have no idea if that's genuine users or crawler bots. If they are real users we need to do something to convince them to register.


Icon Zero Identity Forums - General - Web Security - Tamper Data


Are you bored? Check out the unaswered threads!

w3bw4rr10r
Member


Avatar
Trainee

Joined: 01/04/2009
Last Seen: 0000-00-00
Experience: 196.8
Points: 60
#1 Tamper Data on 01/01/1970 00:00
There is a flash game that submits POST_DATA to a web server, which then uses PHP to save it in a MySQL table.
Problem is, sometimes I can change the value successfully with TD but sometimes not. I think, it may be due to the session ID or whatever...e.g.
Code Highlighting :: Select Code
score=0%2E000&jst%5Fresultid=703460&jst%5Ftournamentid=5&jst%5Fsessionid=25fca28991b66d815e0f1f058390c404&jst%5Fuserid=140082

I usually edit the number immediately after the score, but a lot of times, it doesn't work. The result ends up being -1, which causes a system error but doesn't get me ranked up...
I'm curious, because the session and result ID are always the same, but could it be in some way tied to the score?
Grindordie
Administrator
Software Engineer

Avatar
ZI Guru

Joined: 11/04/2007
Last Seen: 0000-00-00
Experience: 1207.57
Points: 1100
#2 on 01/01/1970 00:00
It may use a Token that is only valid once...
Once you resubmit the score using the same token, it updates the score to -1. (Simple prevention to replay attacks)

So, try acting as a man-in-the-middle; modify the data before it's sent originally, or find the token and form your own request.

That's not a bug, that's an unexpected feature

phpFort - light-weight content management system.
vs4vijay
Member
Hacked!!!....

Avatar
ZI Guru

Joined: 10/02/2008
Last Seen: 2011-03-28
Experience: 1129.58
Points: 930
#3 on 01/01/1970 00:00
which game is that and which site is that...........

Image
Image
Image
kiddies
Member


Avatar
Newbie

Joined: 08/02/2009
Last Seen: 0000-00-00
Experience: 45
Points: 10
#4 on 01/01/1970 00:00
that tokeen???


Who is watching forums


Users viewing this page: Guests (1)
Users viewing the forum: 0