• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Regarding Signatures

I am sure mostly everyone has noticed the colorful signatures certain members have, and for the most part they do not bother me, except I believe some members have taken it too far. I was under the impression many members like FT due to the fact that it is uniform and professional looking. I also thought that everyone was going to refrain from doing this until it was fixed. But, then again one could just turn sigs off.

Examples
(recently someone had size 20+ font in their sig)

I am not complaining at all, I just would like to discuss the situation and maybe gain some more knowledge and possibly prevent some future trouble. 🙂



EDIT: Also I am curious to how the Mods and Jason feel about this. Is it okay to do as long as its tasteful?


 
Originally posted by: JDrake
Repost

If you took the time to read the thread, you would realize I mentioned that thread in the OP, the reason why I have created this thread is to add a poll, and because that was a more narrow topic thread, if it was not dead. 🙂
 
Originally posted by: F22 Raptor
Originally posted by: JDrake
Repost

If you took the time to read the thread, you would realize I mentioned that thread in the OP, the reason why I have created this thread is to add a poll, and because that was a more narrow topic thread, if it was not dead. 🙂
Sorry, didn't see a Poll.
But like two weeks ago when I PMed the Mods about it, here was their response:

AnandTech Moderator Hmmm...
I think it will be easier to just ban everyone who messed with the code. They know it isn't allowed.
I'll bring it up with the other Mods. Thanks for the heads up. 05/14/2006 09:05 PM
 
Originally posted by: JDrake
Originally posted by: F22 Raptor
Originally posted by: JDrake
Repost

If you took the time to read the thread, you would realize I mentioned that thread in the OP, the reason why I have created this thread is to add a poll, and because that was a more narrow topic thread, if it was not dead. 🙂
Sorry, didn't see a Poll.
But like two weeks ago when I PMed the Mods about it, here was their response:

AnandTech Moderator Hmmm...
I think it will be easier to just ban everyone who messed with the code. They know it isn't allowed.
I'll bring it up with the other Mods. Thanks for the heads up. 05/14/2006 09:05 PM

Thanks for the information, I assumed it was not allowed, but not quite sure.
 
The webmasters need to fix this asap, because it's a major secuirty risk.

Example : My sig. Just hover over it.

EDIT : Removed it. Don't want to give anyone any ideas.
 
they know it isn't allowed? where is that posted?

-------------------------------------------------------------------------------------------
It is very strongly recommmended that one does not attempt to exploit any weaknesses in Fusetalk for ones egotistical satisfaction.

Anandtech Moderator
 
Originally posted by: iamwiz82
This is the second time in a month it's happened, and as far as I can tell, it's the same people doing it.
Well, originally it was just Reel, Minendo, and myself, IIRC.
Now loke, chuckywang, and felixthekat have jumped onto the bandwagon and Reel/myself have removed it
 
Of course it is going to happen. This forum isn't exactly 'self policing'. Too many 'kids' who don't care. *shrug* this is a bug with fusetalk and poor serverside validation.

Oh, and on the poll topic: I think sigs should be limited to actual sigs. Something like at most 1 carage return. there are too many sigs that are 5+ lines, which just makes the forum look like crap. Really, my sig is one line too long. The oldsmoboat thing is just in there because... well, just because.
 
Originally posted by: Baked
Ok, this text hack thing has gone too far now. :|

And, Rip The Jacker's sig now contains a box that goes over the forums formatting background.

Maybe a couple of vacations would send the message for those who so stupidly disregard the warning from the moderators and show such balatent disrespect for authority.
 
Wow. This is just fantastic. You're complaining about the problem, then drawing even more attention to it by specifying exactly how to find out how to do it.

I've already contacted the mods personally and told them the problem, the security risks (forced access to accounts, even AT Mod) and how to prevent it. Now we just have to wait for them to forward it to the webmaster.
 
Originally posted by: HamburgerBoy
So long as they cause no real damage to the forums I'm fine with them.

Originally posted by: Baked
Ok, this text hack thing has gone too far now. :|

Meh, it's just a little prank. Really, how long does it take you to log back into your account?

It's not the problem of having to log in again, but rather that he's showing people how to abuse it more than ever. I mean, there is a huge risk here that, if exploited as I've shown to the mods that it can be done, could result in forced access to any account.
 
Originally posted by: LoKe
Originally posted by: HamburgerBoy
So long as they cause no real damage to the forums I'm fine with them.

Originally posted by: Baked
Ok, this text hack thing has gone too far now. :|

Meh, it's just a little prank. Really, how long does it take you to log back into your account?

It's not the problem of having to log in again, but rather that he's showing people how to abuse it more than ever. I mean, there is a huge risk here that, if exploited as I've shown to the mods that it can be done, could result in forced access to any account.
Guys, don't get your panties in a bunch. Loke is speaking BS, fyi. There's no way, with javascript, CSS, html, etc that this would be possible. Especially not in the 250 character limit in the signature. The only thing that might be half possible would be a CG and with that, the abuser doesn't even know the person's password, they can just post on your name :/ and that's highly unlikely
 
Originally posted by: JDrake
Originally posted by: LoKe
Originally posted by: HamburgerBoy
So long as they cause no real damage to the forums I'm fine with them.

Originally posted by: Baked
Ok, this text hack thing has gone too far now. :|

Meh, it's just a little prank. Really, how long does it take you to log back into your account?

It's not the problem of having to log in again, but rather that he's showing people how to abuse it more than ever. I mean, there is a huge risk here that, if exploited as I've shown to the mods that it can be done, could result in forced access to any account.
Guys, don't get your panties in a bunch. Loke is speaking BS, fyi. There's no way, with javascript, CSS, html, etc that this would be possible. Especially not in the 250 character limit in the signature. The only thing that might be half possible would be a CG and with that, the abuser doesn't even know the person's password, they can just post on your name :/ and that's highly unlikely

That's what I was getting at, you would be logged in as AnandTech Moderator. Are you telling me that wouldn't be damaging enough?
 
Originally posted by: LoKe
That's what I was getting at, you would be logged in as AnandTech Moderator. Are you telling me that wouldn't be damaging enough?
So, uhhh.. what would you do as a moderator? Ban a few people, make a few posts? The mods can't do anything besides lock/delete topics (and edit/delete posts), ban people, and make posts. Everything is logged, and once they figured out someone was on their account, a simple password change would forcefully log the intruder out. They could run the IP of the intruder in their database, figure out who it was, and then permaban that member.
AND, plus, this is all considering that logging into mod's account automatically gives the user mod-ability. For all we know, they probably have a special log-in page/CP just for them that is IP-verified (Forbidden Access, etc)
 
Back
Top