We might restart the forum today

DanP

Administrator
Staff member
vacBacker
Feedback
5 (100%)
Credits
2,172CR
rcantor77 said:
What an interesting thread this has been... it is great to see that bugs and security issues are actively getting fixed by the Admin and Dev teams but who knew that as a casual member you are able to hack a forum and then buy your way out of being banned.

The world just gets more curious by the day...
smiley3.gif

That's just a wanky thing to say. Are you just trying to stir up trouble or something? This post has zero use otherwise. The only thing more foolish than what you've said is BM taking it to heart and self banning himself. Grow the f**k up ffs.
 

trm

Who loves you, and who do you love?
Feedback
2 (100%)
Credits
2,876CR
Donations have nothing to do with this, other than BM identified a vulnerability in that part of the system.

You cannot buy favour, buy yourself out of trouble, or buy a good reputation here.
 

Alpha1

Do the Shake and 'VAC
Staff member
vacBacker
Feedback
95 (99%)
Credits
5,368CR
rcantor77 said:
Ravage said:
BM has been advised that notifying us of a loophole
should have been the correct course rather than just sitting back and
waiting for the fireworks.

Future instances will certainly not be so leniently dealt with!

Alpha1 said:
As was said - we welcome positive 'penetration testing' and/or notification of any loopholes in custom development.

So is it acceptable or not... or is it only the accepted if you donate money to the forum...?

Hey dude,

If it is done in malice then no it isn't acceptable. Donate 1 Million - it still isn't acceptable.

You can see ealier in this thread I've clarified if a loophole exists then it is in the interest of the member that found it to let an Admin know ASAP (privately), so it can be fixed. That is welcomed if we missed something in our development BETA testing.

Using it maliciously, not informing us, or making it painful for us to clean up isn't acceptable - we all have day jobs and this is done in our spare time. In this instance it allowed you to only add points to your account which we have now closed - so nothing that would cause issue to the forum for all members, however that doesn't mean it wouldn't have been an issue if it was used maliciously - for example adding a continual additiona of points to all members or select members or something.

So in all honesty we are thankful that is has been brought up, but just need clarification to ensure next time if something is found it is brought to our attention in the way we require.

We have made positive steps to ensure if anything is found in the future - it is brought to our attention in the method we have asked. If that isn't the case, then obviously that's not going to be acceptable.

We'll get this written into our FAQ ASAP and possibly look to extend our BETA testing team.

Stay tuned.
 

Alpha1

Do the Shake and 'VAC
Staff member
vacBacker
Feedback
95 (99%)
Credits
5,368CR
And just to be clear, there's no real hack here other than refreshing your donation window to re-add what you have already donated - which re-added the points but did not take another Paypal payment.

So 'hack' is a word that is totally OTT here. If a real hack had happened - then further action would be taken - probably using my fists as UKVAC is something I personally put a lot of effort into. Just check my guns out in the Barn thread
smiley2.gif


So hopefully that is all everyone needs to fully understand the situation.

Hacking (real hacking) is not acceptable! You would be banned, drawn and quartered and punched repeatedly in the face by me.

Bringing to the attention a loophole in personal code UKVAC Dev guys have written is welcome - but please do it in a positive way and privately.

Exploiting a loophole in personal UKVAC Dev guys code and not telling us is just a silly thing to do and means we have to clean it all up, will 99% annoy us and probably make us consider further action including banning.

I hope this gives a full and clear understanding of where we stand. We will write this up as I said so there is no misconception about what is right, wrong, or just a crappy thing to do.

Thanks.
 

Equites

Chief Sheesher®
vacBacker
Feedback
35 (100%)
Credits
3,305CR
rcantor77 said:
Ravage said:
BM has been advised that notifying us of a loophole
should have been the correct course rather than just sitting back and
waiting for the fireworks.

Future instances will certainly not be so leniently dealt with!

Alpha1 said:
As was said - we welcome positive 'penetration testing' and/or notification of any loopholes in custom development.

So is it acceptable or not... or is it only the accepted if you donate money to the forum...?

In a nutshell, hacking or even testing on a live forum is not acceptable, and I share your concerns. However, we are terribly lucky to have awesome Admin staff on this forum and I have absolutely no doubt that they have dealt with this the appropriate way.

Let Admin do their job and lets all relax and chill out man.
 

drip dripper

Newbie
Credits
6CR
i am quite new here , but feel like i must say something .

bristol martin could have kept stum . he could have found more he may know more hacks and ways of this and that

if it can be locked it can be unlocked that goes for anything , any system anywhere in the world

we all know this .

i dont know bristol martin , i just dont like what i am reading .

i bet people have been banned and blocked for lesser offences .

seems like because bristol martin stumps up dough for raids he is ammune .

very clicky it is here indeed .

i dont know the answer all i know is i had to speak even if it wont make sence to anyone otherthan me
 

Alpha1

Do the Shake and 'VAC
Staff member
vacBacker
Feedback
95 (99%)
Credits
5,368CR
Hi,

Honest to God guys if we had really been hacked BristolMartin would be banned and I would have probably gone further.

He literally pressed F5 on his keyboard after he donated.

We have already dealt with this privately, and I wanted to keep it private - but just for the record, yes if he did it again he would be banned.

I do not care if you are a millionaire a billionaire or just a regular guy - you would ALL get treated the same. drip dripper - if you did what he did - our response would be the same. If Equites, rcantor77, PAC-MAN or any other member did the same - our response would be the same.

Our statement is we are going to update our FAQ to include handling affairs like this including updating how to report bugs and also how malicious attacking will be dealt with.

Everyone reading this needs to believe what I am saying.

This is NOT about money
This is NOT about getting cabs from a Barn Raid - I invited everyone from this forum to go on an arcade adventure - I could have quite easily performed this in the quiet with a handful of known friends or just done it myself.
This is NOT about anything other than what I have genuinely stated.

If BristolMartin had _really_ _honest_ _to_ _God_ hacked this place, he would have got a punch in the face and a ban. That is the Gods honest truth.

Just as general statement about banning for lesser offences.

We have only ever banned one person. That person is RITCHIE100, and that is only after we gave him multiple chances of redemption.

We are not a banning forum unless it is entirely justified. In this instance - we saw the bug in our code ourselves, and realised it isn't a hack, pressing a key on your keyboard isn't hacking.

We need to remove the money element from this, UKVAC judges people equally. We always will, as that is what is fair and just.
 

chubsta

Active member
Feedback
4 (100%)
Credits
526CR
I don't think that the issue is one of the forum being cliquey, I think one of the great strengths of this particular forum is that it is far from being cliquey, it does not have many of the rules of other sites and as a result polices itself very well. In this respect I don't think any forum donations etc have anything to do with the lack of a ban, more that the owners do not want to start coming down on people which is not part of the forum ethos.

Of course if bm wants to throw his toys out of the pram and ban himself for a few weeks then let him, although it does seem a little attention seeking to me, as does this whole episode...
 

JohnBud

There's only one JB, only one JB!
Feedback
2 (100%)
Credits
429CR
It's all bollox, martin found a flaw, no hacking was involved, endex. If it was malicious he would be banned, and perhaps hacked himself. The guys running the show here are more than capable of being malicious. I lost at least a squillion points, but hey ho, I'm still on the go.
 

RaveN

Active member
vacBacker
Feedback
1 (100%)
Credits
1,325CR
This is a community website, not a bank. We have a lot of technical people on this site and we could all sit here trying various sql injections etc. to find bugs, but really what is the point... it works if people use it right, and doing this kind of thing just adds more workload to the admins.

If he has self imposed a ban on himself, can we quickly arrange another raid/group buy before he returns and buys everything? (Too early for jokes yet?
smiley2.gif
)
 

IDCHAPPY

KANFU Master
vacBacker
Feedback
9 (100%)
Credits
1,523CR
Alpha1 said:
Hi,

Honest to God guys if we had really been hacked BristolMartin would be banned and I would have probably gone further.

He literally pressed F5 on his keyboard after he donated.

We have already dealt with this privately, and I wanted to keep it private - but just for the record, yes if he did it again he would be banned.

I do not care if you are a millionaire a billionaire or just a regular guy - you would ALL get treated the same. drip dripper - if you did what he did - our response would be the same. If Equites, rcantor77, PAC-MAN or any other member did the same - our response would be the same.

Our statement is we are going to update our FAQ to include handling affairs like this including updating how to report bugs and also how malicious attacking will be dealt with.

Everyone reading this needs to believe what I am saying.

This is NOT about money
This is NOT about getting cabs from a Barn Raid - I invited everyone from this forum to go on an arcade adventure - I could have quite easily performed this in the quiet with a handful of known friends or just done it myself.
This is NOT about anything other than what I have genuinely stated.

If BristolMartin had _really_ _honest_ _to_ _God_ hacked this place, he would have got a punch in the face and a ban. That is the Gods honest truth.

Just as general statement about banning for lesser offences.

We have only ever banned one person. That person is RITCHIE100, and that is only after we gave him multiple chances of redemption.

We are not a banning forum unless it is entirely justified. In this instance - we saw the bug in our code ourselves, and realised it isn't a hack, pressing a key on your keyboard isn't hacking.

We need to remove the money element from this, UKVAC judges people equally. We always will, as that is what is fair and just.

Totally man, Chubsta and JB stole everything I was going to say though
smiley36.gif
 
G

Guests

Guest
IDCHAPPY said:
Alpha1 said:
Hi,

Honest to God guys if we had really been hacked BristolMartin would be banned and I would have probably gone further.

He literally pressed F5 on his keyboard after he donated.

We have already dealt with this privately, and I wanted to keep it private - but just for the record, yes if he did it again he would be banned.

I do not care if you are a millionaire a billionaire or just a regular guy - you would ALL get treated the same. drip dripper - if you did what he did - our response would be the same. If Equites, rcantor77, PAC-MAN or any other member did the same - our response would be the same.

Our statement is we are going to update our FAQ to include handling affairs like this including updating how to report bugs and also how malicious attacking will be dealt with.

Everyone reading this needs to believe what I am saying.

This is NOT about money
This is NOT about getting cabs from a Barn Raid - I invited everyone from this forum to go on an arcade adventure - I could have quite easily performed this in the quiet with a handful of known friends or just done it myself.
This is NOT about anything other than what I have genuinely stated.

If BristolMartin had _really_ _honest_ _to_ _God_ hacked this place, he would have got a punch in the face and a ban. That is the Gods honest truth.

Just as general statement about banning for lesser offences.

We have only ever banned one person. That person is RITCHIE100, and that is only after we gave him multiple chances of redemption.

We are not a banning forum unless it is entirely justified. In this instance - we saw the bug in our code ourselves, and realised it isn't a hack, pressing a key on your keyboard isn't hacking.

We need to remove the money element from this, UKVAC judges people equally. We always will, as that is what is fair and just.

Totally man, Chubsta and JB stole everything I was going to say though
smiley36.gif

and me.......the fookers!!
smiley36.gif
 

IDCHAPPY

KANFU Master
vacBacker
Feedback
9 (100%)
Credits
1,523CR
RaveN said:
This is a community website, not a bank. We have a lot of technical people on this site and we could all sit here trying various sql injections etc. to find bugs, but really what is the point... it works if people use it right, and doing this kind of thing just adds more workload to the admins.

If he has self imposed a ban on himself, can we quickly arrange another raid/group buy before he returns and buys everything? (Too early for jokes yet?
smiley2.gif
)

Never too early for some humour
smiley17.gif
 

IDCHAPPY

KANFU Master
vacBacker
Feedback
9 (100%)
Credits
1,523CR
PAC-MAN said:
IDCHAPPY said:
Alpha1 said:
Hi,

Honest to God guys if we had really been hacked BristolMartin would be banned and I would have probably gone further.

He literally pressed F5 on his keyboard after he donated.

We have already dealt with this privately, and I wanted to keep it private - but just for the record, yes if he did it again he would be banned.

I do not care if you are a millionaire a billionaire or just a regular guy - you would ALL get treated the same. drip dripper - if you did what he did - our response would be the same. If Equites, rcantor77, PAC-MAN or any other member did the same - our response would be the same.

Our statement is we are going to update our FAQ to include handling affairs like this including updating how to report bugs and also how malicious attacking will be dealt with.

Everyone reading this needs to believe what I am saying.

This is NOT about money
This is NOT about getting cabs from a Barn Raid - I invited everyone from this forum to go on an arcade adventure - I could have quite easily performed this in the quiet with a handful of known friends or just done it myself.
This is NOT about anything other than what I have genuinely stated.

If BristolMartin had _really_ _honest_ _to_ _God_ hacked this place, he would have got a punch in the face and a ban. That is the Gods honest truth.

Just as general statement about banning for lesser offences.

We have only ever banned one person. That person is RITCHIE100, and that is only after we gave him multiple chances of redemption.

We are not a banning forum unless it is entirely justified. In this instance - we saw the bug in our code ourselves, and realised it isn't a hack, pressing a key on your keyboard isn't hacking.

We need to remove the money element from this, UKVAC judges people equally. We always will, as that is what is fair and just.

Totally man, Chubsta and JB stole everything I was going to say though
smiley36.gif

and me.......the fookers!!
smiley36.gif

I'm gonna ban them for it
smiley17.gif
smiley36.gif
 
Top