Discuss Scratch
- Discussion Forums
- » Advanced Topics
- » ocular - scratch forum info
- herohamp
-
Scratcher
1000+ posts
ocular - scratch forum info
It’s well understood they have no clue what’s happening now that they’be compared the private code to a password.1. i have already worked with hampton to patch the bug in ocular.Okay, thanks! And I told jeffalo about the patch for the redirect vuln(it is a vuln for e.g youtube doesn't leak your password when you get redirected) and I hope he patches it.It is not since the patch where the final server authenticating can get what the original redirect was and verify it.THE PRIVATE CODE BEING EXPOSED IN THAT MANOR IS NOT A SECURITY FLAW AS WE’VE GONE OVER.It is if it redirects to a website that sends it to a server. (But not really a true security flaw I think)
2. your private code is not a password. it's useless unless the redirect location was ocular.jeffalo.net, so you can't intercept it with a redirect to your wrbsite.
3. it feels like you're already aware that the bug is patched, and you're still trying to get attention from it. (i feel this way because we've both explained to you that the bug is fixed but you keep making posts like this)
- dertermenter
-
Scratcher
1000+ posts
ocular - scratch forum info
Ocular has been broken for a week.. anything I can do on my end to fix it?
- CST1229
-
Scratcher
1000+ posts
ocular - scratch forum info
I think that they were referring to the FluffyScratch Scratch project UI, in that case it's not a PR. herohamp updated it a while back.Also love the new UI!!I think it was a PR made months ago that was just merged now.
Remember when it was Scratch Cat on a space background?
- Jeffalo
-
Scratcher
1000+ posts
ocular - scratch forum info
Ocular has been broken for a week.. anything I can do on my end to fix it?i believe search is frozen if that's what you mean. - that's out of my control
- herohamp
-
Scratcher
1000+ posts
ocular - scratch forum info
Btw The private key is still visible on redirects, but it being seen is NOT a vulnOk, sorry, I didn't know it was fixed.It’s well understood they have no clue what’s happening now that they’be compared the private code to a password.1. i have already worked with hampton to patch the bug in ocular.Okay, thanks! And I told jeffalo about the patch for the redirect vuln(it is a vuln for e.g youtube doesn't leak your password when you get redirected) and I hope he patches it.It is not since the patch where the final server authenticating can get what the original redirect was and verify it.THE PRIVATE CODE BEING EXPOSED IN THAT MANOR IS NOT A SECURITY FLAW AS WE’VE GONE OVER.It is if it redirects to a website that sends it to a server. (But not really a true security flaw I think)
2. your private code is not a password. it's useless unless the redirect location was ocular.jeffalo.net, so you can't intercept it with a redirect to your wrbsite.
3. it feels like you're already aware that the bug is patched, and you're still trying to get attention from it. (i feel this way because we've both explained to you that the bug is fixed but you keep making posts like this)
- dertermenter
-
Scratcher
1000+ posts
ocular - scratch forum info
Yeah, that's what's broken for me, oh wellOcular has been broken for a week.. anything I can do on my end to fix it?I believe search is frozen if that's what you mean. - that's out of my control

IT HAS BEEN FIXED!!!
Last edited by dertermenter (Dec. 17, 2021 14:47:29)
- herohamp
-
Scratcher
1000+ posts
ocular - scratch forum info
It's still private, did you know that when you log into a website your password is visible in plaintext if you check the POST dataBtw The private key is still visible on redirectsThen it is public code not private code LOL![]()
It would be no different if we sent it in POST data. and if you argue HTTPS protects the password in post data (which it does from MITM), HTTPS also protects data included in HTTP Query Parameters.Last edited by herohamp (Dec. 17, 2021 20:54:09)
- TurtleLegos
-
Scratcher
1000+ posts
ocular - scratch forum info
Chill. It wasn't “sorted out” when I posted.Bro, this is now sorted out, they didn't take it seriously, so I thought it is not severe, but I will demo my concept and I hope everyone will know better then.Please check this:Dude. You have posted on Herohamp and Jeffalo's profiles. You made a project about it then (partially using common sense), made your own topic, and now you post here? If you know so much about cybersecurity, you probably know not to publicly announce vulns. It's like me saying that I love anime one day, (I totally do) but then I say, “I DON'T WATCH ANIME!” It doesn't make any sense.
https://scratch.mit.edu/discuss/topic/565800/
and fix the vuln!
- VeryFamus
-
Scratcher
1000+ posts
ocular - scratch forum info
I found an Ocular bug (not sure if this happens for others, but) basically when you create an account, everyone’s post count is set to “0+”. Could you fix this?
Last edited by VeryFamus (Dec. 23, 2021 03:55:13)
- Jeffalo
-
Scratcher
1000+ posts
ocular - scratch forum info
I found an Ocular bug (not sure if this happens for others, but) basically when you create an account, everyone’s post count is set to “0+”. Could you fix this?i think this is just a bug with scratchdb right now. it is currently under maintenance.
Wowie king of the 152nd page
- VeryFamus
-
Scratcher
1000+ posts
ocular - scratch forum info
Ok, thanks!I found an Ocular bug (not sure if this happens for others, but) basically when you create an account, everyone’s post count is set to “0+”. Could you fix this?i think this is just a bug with scratchdb right now. it is currently under maintenance.
Wowie king of the 152nd page
- brourbeinsus
-
Scratcher
100+ posts
ocular - scratch forum info
Me when the google images:

Edit: I just looked up brourbeinsus and found this what

Edit: I just looked up brourbeinsus and found this what
Last edited by brourbeinsus (Dec. 23, 2021 03:52:56)
- TurtleLegos
-
Scratcher
1000+ posts
ocular - scratch forum info
Me when the google images:cursed
Edit: I just looked up brourbeinsus and found this what
- ScolderCreations
-
Scratcher
1000+ posts
ocular - scratch forum info
a little downtimewe do a little downtime

- Jeffalo
-
Scratcher
1000+ posts
ocular - scratch forum info
a little downtimenothing better than some late night christmas eve package upgrades

Last edited by Jeffalo (Dec. 24, 2021 22:34:14)
- Chiroyce
-
Scratcher
1000+ posts
ocular - scratch forum info
a little downtimenothing better than some late night christmas eve package upgrades

So I guess…. Merry Christmas!!!
- mybearworld
-
Scratcher
1000+ posts
ocular - scratch forum info
this is white now? is this intentional?


- Chiroyce
-
Scratcher
1000+ posts
ocular - scratch forum info
this is white now? is this intentional?Looks like it depends on browser
me on Firefox with macOS

