Login
Sign Up


You are using the mobile version of the forum, some features have been disabled to have it responsive.
Limelight Reunion 2024 - v4b1Limelight Discord
Ares Defence Services Discord
Limelight Reunion 2024 - v4b1Limelight DiscordAres Defence Services Discord

receiptDevelopment Blog:

Development Contributor Workflow

receiptHR Blog:

What *are* they doing over there?

receiptTeacher Blog:

Insight into the Teacher Team

receiptDevelopment Blog:

Infrastructure Upgrade 11/2019

receiptDevelopment Blog:

how suggestions???

receiptDevelopment Blog:

Planning for the future.


This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Adam james's unban request
Adam James radio_button_checked
User
Registered User
Posts: 71
Threads: 11
Likes Given: 81
Likes Recieved: 44 in 32 posts
Joined: Aug 2015
Reputation: 0
#1
Dec 5, 2015, 10:01 PM
Your Name: [RG] Operation

Ban ID: 114

Banned by: Temar

Server: n/a

Ban Reason: "Trying to hack the website"

Why should you be unbanned?: I feel as if the ban was unfair, because I never intended to hack the website. My intentions were to find exploits I could report to Temar or another Super Admin. I noticed while viewing client side source code on google chrome that a part of the donation page was vulnerable to XSS (Cross site scripting) I a few seconds after I found it, and tested it out to see if it was just a false positive or not., then reported it to Enzyme,
I would also like to state that it was a POST xss injection, and cant really be used to even exploit anything due to it being post, you cannot grab cookies, etc. It's pretty much useless unless you wanna just test out your skills.
I feel it is unfair because I didnt even mean to find it nor did I intend to exploit it.

Thanks,

Adam/Operation
Evidence: N/A
George radio_button_checked
Actively inactive
Veteran Member
Posts: 1,261
Threads: 28
Likes Given: 716
Likes Recieved: 1433 in 530 posts
Joined: Aug 2015
Reputation: 20
#2
Dec 9, 2015, 05:54 PM
While it's understandable that you were looking for vulnerabilities in the donation page so you could report them, the problem is that you gave us no prior warning that you were going to do so. Therefore, when we find out someone is trying to find vulnerabilities out of the blue, it does look suspicious.

At the end of the day it's up to Temar or Faustie whether or not you should be unbanned.
[Image: olA44b8.png]
(This post was last modified: Dec 9, 2015, 05:55 PM by George.)
Nacreas radio_button_checked
CityRP 2 Admin
Core Staff
Posts: 1,986
Threads: 148
Likes Given: 881
Likes Recieved: 966 in 464 posts
Joined: Aug 2015
Reputation: 34
#3
Dec 15, 2015, 02:46 PM
If your intention wasn't malicious, you would have requested permission from staff to carry-out this test. From our point of view, you've attempted to find vulnerabilities in our website which could potentially give you access to things which you're not supposed to have access to. At this stage, we see no reason to unban you.

Do you have anything else you'd like to add?
[Image: H9hqjyZ.png]
(This post was last modified: Dec 15, 2015, 03:14 PM by Nacreas.)
Adam James radio_button_checked
User
Registered User
Posts: 71
Threads: 11
Likes Given: 81
Likes Recieved: 44 in 32 posts
Joined: Aug 2015
Reputation: 0
#4
Dec 16, 2015, 10:00 PM
(Dec 15, 2015, 02:46 PM)Nacreas Wrote: you've attempted to find vulnerabilities in our website which could potentially give you access to things which you're not supposed to have access to.

XSS can't be used for shit. Even if I was to get Temar or another admins login cookie from XSS i wouldn't beable to use it because mybb has cookie security.
Enzyme radio_button_checked
Supervising Administrator - HR
Veteran Member
Posts: 2,443
Threads: 115
Likes Given: 1110
Likes Recieved: 2721 in 820 posts
Joined: Aug 2015
Reputation: 45
#5
Dec 18, 2015, 06:47 PM
You should have alerted/gotten permission from the staff before doing what you did Adam.
What you did is viewed upon as an attempt on hacking our website, something which we do not take lightly.

As I see it, the ban itself is valid. What can be discussed however is if you should be given another chance or not.

Are you trying to appeal this current ban in an attempt to have it removed or are you asking for another chance?
Sincerely, Enzyme
[Image: WWBN6ow.gif]
Adam James radio_button_checked
User
Registered User
Posts: 71
Threads: 11
Likes Given: 81
Likes Recieved: 44 in 32 posts
Joined: Aug 2015
Reputation: 0
#6
Dec 21, 2015, 03:40 AM
Sorry went on a trip to New York City.

I guess ill try for a second chance.
Faustie radio_button_checked
Veteran
Veteran Member
Posts: 3,039
Threads: 305
Likes Given: 1050
Likes Recieved: 2419 in 844 posts
Joined: Aug 2015
Reputation: 25
#7
Jan 6, 2016, 03:57 PM
Denied.

Attempting to find exploits without prior permission from either myself or Temar is unacceptable. There are only a few very special circumstances in which we would allow players to attempt to find exploits, and in all of those cases prior permission is a requirement.

Given that you reported the minor issue you found to Enzyme, I'll allow you to make a new unban request in March and we can review then. However, I can't allow this to go without punishment, else others may be encouraged to do what you did.




Users browsing this thread: 1 Guest(s)