Discuss Scratch

herohamp
Scratcher
1000+ posts

ocular - scratch forum info

Jeffalo wrote:

slgsan-encrypted wrote:

herohamp wrote:

CST1229 wrote:

herohamp wrote:

THE PRIVATE CODE BEING EXPOSED IN THAT MANOR IS NOT A SECURITY FLAW AS WE’VE GONE OVER.
It is if it redirects to a website that sends it to a server. (But not really a true security flaw I think)
It is not since the patch where the final server authenticating can get what the original redirect was and verify it.
Okay, thanks! And I told jeffalo about the patch for the redirect vuln(it is a vuln for e.g youtube doesn't leak your password when you get redirected) and I hope he patches it.
1. i have already worked with hampton to patch the bug in ocular.
2. your private code is not a password. it's useless unless the redirect location was ocular.jeffalo.net, so you can't intercept it with a redirect to your wrbsite.
3. it feels like you're already aware that the bug is patched, and you're still trying to get attention from it. (i feel this way because we've both explained to you that the bug is fixed but you keep making posts like this)
It’s well understood they have no clue what’s happening now that they’be compared the private code to a password.
dertermenter
Scratcher
1000+ posts

ocular - scratch forum info

Ocular has been broken for a week.. anything I can do on my end to fix it?
CST1229
Scratcher
1000+ posts

ocular - scratch forum info

god286 wrote:

Chiroyce wrote:

Also love the new UI!!
I think it was a PR made months ago that was just merged now.
I think that they were referring to the FluffyScratch Scratch project UI, in that case it's not a PR. herohamp updated it a while back.
Remember when it was Scratch Cat on a space background?
Jeffalo
Scratcher
1000+ posts

ocular - scratch forum info

dertermenter wrote:

Ocular has been broken for a week.. anything I can do on my end to fix it?
i believe search is frozen if that's what you mean. - that's out of my control
herohamp
Scratcher
1000+ posts

ocular - scratch forum info

slgsan-encrypted wrote:

herohamp wrote:

Jeffalo wrote:

slgsan-encrypted wrote:

herohamp wrote:

CST1229 wrote:

herohamp wrote:

THE PRIVATE CODE BEING EXPOSED IN THAT MANOR IS NOT A SECURITY FLAW AS WE’VE GONE OVER.
It is if it redirects to a website that sends it to a server. (But not really a true security flaw I think)
It is not since the patch where the final server authenticating can get what the original redirect was and verify it.
Okay, thanks! And I told jeffalo about the patch for the redirect vuln(it is a vuln for e.g youtube doesn't leak your password when you get redirected) and I hope he patches it.
1. i have already worked with hampton to patch the bug in ocular.
2. your private code is not a password. it's useless unless the redirect location was ocular.jeffalo.net, so you can't intercept it with a redirect to your wrbsite.
3. it feels like you're already aware that the bug is patched, and you're still trying to get attention from it. (i feel this way because we've both explained to you that the bug is fixed but you keep making posts like this)
It’s well understood they have no clue what’s happening now that they’be compared the private code to a password.
Ok, sorry, I didn't know it was fixed.
Btw The private key is still visible on redirects, but it being seen is NOT a vuln
dertermenter
Scratcher
1000+ posts

ocular - scratch forum info

Jeffalo wrote:

dertermenter wrote:

Ocular has been broken for a week.. anything I can do on my end to fix it?
I believe search is frozen if that's what you mean. - that's out of my control
Yeah, that's what's broken for me, oh well

IT HAS BEEN FIXED!!!

Last edited by dertermenter (Dec. 17, 2021 14:47:29)

herohamp
Scratcher
1000+ posts

ocular - scratch forum info

slgsan-encrypted wrote:

herohamp wrote:

Btw The private key is still visible on redirects
Then it is public code not private code LOL
It's still private, did you know that when you log into a website your password is visible in plaintext if you check the POST data It would be no different if we sent it in POST data. and if you argue HTTPS protects the password in post data (which it does from MITM), HTTPS also protects data included in HTTP Query Parameters.

Last edited by herohamp (Dec. 17, 2021 20:54:09)

TurtleLegos
Scratcher
1000+ posts

ocular - scratch forum info

slgsan-encrypted wrote:

TurtleLegos wrote:

slgsan-encrypted wrote:

Please check this:
https://scratch.mit.edu/discuss/topic/565800/
and fix the vuln!
Dude. You have posted on Herohamp and Jeffalo's profiles. You made a project about it then (partially using common sense), made your own topic, and now you post here? If you know so much about cybersecurity, you probably know not to publicly announce vulns. It's like me saying that I love anime one day, (I totally do) but then I say, “I DON'T WATCH ANIME!” It doesn't make any sense.
Bro, this is now sorted out, they didn't take it seriously, so I thought it is not severe, but I will demo my concept and I hope everyone will know better then.
Chill. It wasn't “sorted out” when I posted.
VeryFamus
Scratcher
1000+ posts

ocular - scratch forum info

I found an Ocular bug (not sure if this happens for others, but) basically when you create an account, everyone’s post count is set to “0+”. Could you fix this?

Last edited by VeryFamus (Dec. 23, 2021 03:55:13)

Jeffalo
Scratcher
1000+ posts

ocular - scratch forum info

VeryFamus wrote:

I found an Ocular bug (not sure if this happens for others, but) basically when you create an account, everyone’s post count is set to “0+”. Could you fix this?

Wowie king of the 152nd page
i think this is just a bug with scratchdb right now. it is currently under maintenance.
VeryFamus
Scratcher
1000+ posts

ocular - scratch forum info

Jeffalo wrote:

VeryFamus wrote:

I found an Ocular bug (not sure if this happens for others, but) basically when you create an account, everyone’s post count is set to “0+”. Could you fix this?

Wowie king of the 152nd page
i think this is just a bug with scratchdb right now. it is currently under maintenance.
Ok, thanks!
brourbeinsus
Scratcher
100+ posts

ocular - scratch forum info

Me when the google images:


Edit: I just looked up brourbeinsus and found this what

Last edited by brourbeinsus (Dec. 23, 2021 03:52:56)

TurtleLegos
Scratcher
1000+ posts

ocular - scratch forum info

brourbeinsus wrote:

Me when the google images:


Edit: I just looked up brourbeinsus and found this what
cursed
Jeffalo
Scratcher
1000+ posts

ocular - scratch forum info

a little downtime
ScolderCreations
Scratcher
1000+ posts

ocular - scratch forum info

Jeffalo wrote:

a little downtime
we do a little downtime
Jeffalo
Scratcher
1000+ posts

ocular - scratch forum info

Jeffalo wrote:

a little downtime
nothing better than some late night christmas eve package upgrades

Last edited by Jeffalo (Dec. 24, 2021 22:34:14)

Chiroyce
Scratcher
1000+ posts

ocular - scratch forum info

Jeffalo wrote:

Jeffalo wrote:

a little downtime
nothing better than some late night christmas eve package upgrades


So I guess…. Merry Christmas!!!
mybearworld
Scratcher
1000+ posts

ocular - scratch forum info

this is white now? is this intentional?
Chiroyce
Scratcher
1000+ posts

ocular - scratch forum info

mybearworld wrote:

this is white now? is this intentional?
Looks like it depends on browser

me on Firefox with macOS

CST1229
Scratcher
1000+ posts

ocular - scratch forum info

Chiroyce wrote:

(#3021)

mybearworld wrote:

this is white now? is this intentional?
Looks like it depends on browser

me on Firefox with macOS

It's specifically a horrible Chrome feature where bold text makes emojis be black and white.

Powered by DjangoBB