» Menu
» OB/Site News
» Articles
» Barafranca News
No news found. Reset in progress?
trepatudo
Registered: | 21:52:02 on 01-03-2011 (5009d 10h 58m 13s ago) |
Role: |
Member
|
Last activity: | 17:08:48 on 14-11-2017 (2559d 15h 41m 27s ago) |
Country: | Portugal |
Comment count: | 51 (0.01 per day) |
Quotes added: | 1 (view all quotes) |
Credits: | 10.00 |
Placed bets: | 0 (0 won / 0 lost / 0 pending) |
23-01 Your thoughts...
15:32:26 - 24-01
kredu at 14:58:40 on 24/01:
How to replicate the bug:
$bullets = (int) $_POST['bullets'];
if ($bullets > 400) //error
else {
//stuff
mysql_query("UPDATE `users` SET `bullets` = `bullets` + ".mysql_real_escape_string($_POST['bullets'])." WHERE `userid` = ".$userid);
}
Great devs. :')
How to replicate the bug:
$bullets = (int) $_POST['bullets'];
if ($bullets > 400) //error
else {
//stuff
mysql_query("UPDATE `users` SET `bullets` = `bullets` + ".mysql_real_escape_string($_POST['bullets'])." WHERE `userid` = ".$userid);
}
Great devs. :')
Actually bug happens in the opposite way, not that way.
When the verification has no cast made but the (int) cast is made after verification...
So 900e+100 would pass verification of <900 and then would be casted to 90000000000 in QUERY.
05-09 Kaboom baby!
23:56:42 - 05-09
How can you even consider that Tempe was in Nazdrovia war?
They shot 2 brugs and went directly to cry on Nazdrovia to deal peace, looks like not even their own members know the family they are in.
They shot 2 brugs and went directly to cry on Nazdrovia to deal peace, looks like not even their own members know the family they are in.
levi toke Boobs HQ ...
lol. where's krulll eviL rbaioa then if it was CCCE... ?
obvious troll idiots
could it be? :o
Kapow, I want to have a son of yours.