Discuss Scratch

blubby4
Scratcher
100+ posts

unknown scratch pages

W1THRD wrote:

blubby4 wrote:

Has this been posted before?

https://scratch.mit.edu/scratch_admin/

Additionally, I know that these also exist (although it's impossible to prove with just the URLs alone (I know these because they're linked from the admin panel on the main page, which I accessed with some client-side trickery. I have NOT hacked the site, and I cannot access any info from there.) )

https://scratch.mit.edu/scratch_admin/tickets
https://scratch.mit.edu/scratch_admin/ip-search/
https://scratch.mit.edu/scratch_admin/email-search/

Edit: just found https://scratch.mit.edu/scratch_admin/page/clear-anon-cache/

What is this “client-side trickery”?
Is it viewing source? Different user agent? Different request parameters??
I wanna try!!!!
I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset
han614698
Scratcher
1000+ posts

unknown scratch pages

The average person won’t be able to access it, but

https://scratch.mit.edu/ip_ban_appeal/(any banned ip)/
EverSwirl
Scratcher
100+ posts

unknown scratch pages

No idea if https://api.scratch.mit.edu/news has been posted before but I know https://scratch.mit.edu/news has. Just like to point out how much different the API page for it is
W1THRD
Scratcher
71 posts

unknown scratch pages

blubby4 wrote:

W1THRD wrote:

blubby4 wrote:

Has this been posted before?

https://scratch.mit.edu/scratch_admin/

Additionally, I know that these also exist (although it's impossible to prove with just the URLs alone (I know these because they're linked from the admin panel on the main page, which I accessed with some client-side trickery. I have NOT hacked the site, and I cannot access any info from there.) )

https://scratch.mit.edu/scratch_admin/tickets
https://scratch.mit.edu/scratch_admin/ip-search/
https://scratch.mit.edu/scratch_admin/email-search/

Edit: just found https://scratch.mit.edu/scratch_admin/page/clear-anon-cache/

What is this “client-side trickery”?
Is it viewing source? Different user agent? Different request parameters??
I wanna try!!!!
I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
PaperMarioFan2022
Scratcher
1000+ posts

unknown scratch pages

BigNate469 wrote:

https://resources.scratch.mit.edu/www/posters-printables/en/ScratchCommunityGuidelinesPoster18x24.pdf

And obscure copy of the CGs.
I know this is from a past conversation, but this should definitely be implemented to Scratch version 3.0. The page looks exactly what it should look like, and the format is much more organized.

But a question: Is this a good thing to suggest in the Suggestion subforums, or was this already suggested before?
Maximouse
Scratcher
1000+ posts

unknown scratch pages

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
ninjaMAR
Scratcher
1000+ posts

unknown scratch pages

Maximouse wrote:

(#887)

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
I've tried to reproduce this, but nothing happens. Admin=true never gets reset back to false for me.
DifferentDance8
Scratcher
1000+ posts

unknown scratch pages

ninjaMAR wrote:

Maximouse wrote:

(#887)

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
I've tried to reproduce this, but nothing happens. Admin=true never gets reset back to false for me.
That's… what you want to do?
FishySquid
Scratcher
91 posts

unknown scratch pages

ninjaMAR wrote:

Maximouse wrote:

(#887)

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
I've tried to reproduce this, but nothing happens. Admin=true never gets reset back to false for me.
well, as https://scratch.mit.edu/scratch_admin/tickets says, the page is VPN protected. We do not have the MIT/Scratch team VPN, so we won't be able to get the scratch_admin pages or admin=true permissions.
DifferentDance8
Scratcher
1000+ posts

unknown scratch pages

FishySquid wrote:

ninjaMAR wrote:

Maximouse wrote:

(#887)

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
I've tried to reproduce this, but nothing happens. Admin=true never gets reset back to false for me.
well, as https://scratch.mit.edu/scratch_admin/tickets says, the page is VPN protected. We do not have the MIT/Scratch team VPN, so we won't be able to get the scratch_admin pages or admin=true permissions.
I tried to “fake” it by setting admin=true manually and blocking scratch.mit.edu/sessions requests which works well to get the admin panel to pop up but it doesn't work for any /scratch_admin/ pages
FishySquid
Scratcher
91 posts

unknown scratch pages

DifferentDance8 wrote:

FishySquid wrote:

ninjaMAR wrote:

Maximouse wrote:

(#887)

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
I've tried to reproduce this, but nothing happens. Admin=true never gets reset back to false for me.
well, as https://scratch.mit.edu/scratch_admin/tickets says, the page is VPN protected. We do not have the MIT/Scratch team VPN, so we won't be able to get the scratch_admin pages or admin=true permissions.
I tried to “fake” it by setting admin=true manually and blocking scratch.mit.edu/sessions requests which works well to get the admin panel to pop up but it doesn't work for any /scratch_admin/ pages
Does the panel work?
DifferentDance8
Scratcher
1000+ posts

unknown scratch pages

FishySquid wrote:

DifferentDance8 wrote:

FishySquid wrote:

ninjaMAR wrote:

Maximouse wrote:

(#887)

W1THRD wrote:

blubby4 wrote:

I just changed the “permissions” cookie so that admin=true, then blocked the request to scratch.mit.edu/session/ so it wouldn't get reset

What tool/software did you use?
This can be done in the browser's developer tools.
I've tried to reproduce this, but nothing happens. Admin=true never gets reset back to false for me.
well, as https://scratch.mit.edu/scratch_admin/tickets says, the page is VPN protected. We do not have the MIT/Scratch team VPN, so we won't be able to get the scratch_admin pages or admin=true permissions.
I tried to “fake” it by setting admin=true manually and blocking scratch.mit.edu/sessions requests which works well to get the admin panel to pop up but it doesn't work for any /scratch_admin/ pages
Does the panel work?
The panel appears but no it doesn't work in that none of the buttons do anything.
Redstone1080
Scratcher
1000+ posts

unknown scratch pages

2016s4m29
Scratcher
500+ posts

unknown scratch pages

Redstone1080 wrote:

Technically not on Scratch, but: https://scratchfoundation.atlassian.net/wiki/spaces/IBE/pages/46465303/VPN+to+Markley
What Is This?
BigNate469
Scratcher
1000+ posts

unknown scratch pages

2016s4m29 wrote:

Redstone1080 wrote:

Technically not on Scratch, but: https://scratchfoundation.atlassian.net/wiki/spaces/IBE/pages/46465303/VPN+to+Markley
What Is This?
I'm guessing something related to the VPN that ST members are required to use, considering

other domains owned by the ST that used to redirect to the main page wrote:

Error 403 Hissssssss! Markley VPN Only.

Last edited by BigNate469 (Sept. 8, 2024 16:30:00)

2016s4m29
Scratcher
500+ posts

unknown scratch pages

BigNate469 wrote:

2016s4m29 wrote:

Redstone1080 wrote:

Technically not on Scratch, but: https://scratchfoundation.atlassian.net/wiki/spaces/IBE/pages/46465303/VPN+to+Markley
What Is This?
I'm guessing something related to the VPN that ST members are required to use, considering
Is It A Mod Panel Or Something?
BigNate469
Scratcher
1000+ posts

unknown scratch pages

2016s4m29 wrote:

BigNate469 wrote:

2016s4m29 wrote:

Redstone1080 wrote:

Technically not on Scratch, but: https://scratchfoundation.atlassian.net/wiki/spaces/IBE/pages/46465303/VPN+to+Markley
What Is This?
I'm guessing something related to the VPN that ST members are required to use, considering
Is It A Mod Panel Or Something?
A VPN is software used to hide your IP, usually by sending your request through several different servers (and making it appear as if those servers sent the request themselves).

All ST members are required to use one, specifically Markley, which the devs seem to be going to lengths to keep what it really is and how it works secret. One of the only reasons that the community knows that it exists at all is scratch.mit.edu/vpn_required , and sites like scratch.pizza that are owned by the ST and used to redirect to the main page, but now say that Markley VPN is required (with some hissing).
ChameleonGamerYT
Scratcher
500+ posts

unknown scratch pages

BigNate469 wrote:

(#898)
One of the only reasons that the community knows that it exists at all is scratch.mit.edu/vpn_required , and sites like scratch.pizza that are owned by the ST and used to redirect to the main page, but now say that Markley VPN is required (with some hissing).
I wonder why it hisses at you for not using Markley
BigNate469
Scratcher
1000+ posts

unknown scratch pages

ChameleonGamerYT wrote:

BigNate469 wrote:

(#898)
One of the only reasons that the community knows that it exists at all is scratch.mit.edu/vpn_required , and sites like scratch.pizza that are owned by the ST and used to redirect to the main page, but now say that Markley VPN is required (with some hissing).
I wonder why it hisses at you for not using Markley
That would be a question for @codubee*.
scratcherman507
Scratcher
63 posts

unknown scratch pages

Will you plzzZzzzzzzzzzzzzzzzzzzzzzzzzzzzz add this one I found its scratch.mit.edu/news

Powered by DjangoBB