Author Topic: FA admins easily manipulated (who knew)  (Read 3245 times)

Kindrift

  • Logik und Idiotie
  • ***
  • Posts: 346
  • E-points: +29/-4
    • View Profile
FA admins easily manipulated (who knew)
« on: January 26, 2010, 05:28:44 pm »
Midday on the 19th, artist Nitro goes mysteriously banned from FA.  The Internet immediately blamed Pinkuh for the unexpected ban, but the truth is, there are admins more incompetent than that.  It seems it was Glaide who banned Nitro, and more astonishing, he kicked Nitro at the request of an anonymous channer. 

Somebody with a mind for social engineering registered the account -xaerun-.  That person then sent Glaide a message.  Roughly, it said, "Nitro has been starting trouble and needs a 48 hour ban, I have to leave so could you do it? Dragoneer has approved the ban." Glaide completely believed that this was his fellow admin Xaerun, and without any more concern in the matter, Glaide banned Nitro. -xaerun- was banned by the next day when an artist noticed the impersonation and reported the account, and another admin restored Nitro's access.

It really seems to be that easy: someone regged a fake admin account, and Glaide didn't check it when they told him to do something.  Glaide was actually de-adminned in 2007. He had done nothing for months and was difficult to reach for admin duties, and in response Dragoneer revoked his admin rights. However, Glaide has severe emotional problems, and he plays on these to get favors. Immediately after his rights were stripped, he cried to Dragoneer and claimed that that it was making him terribly depressed to not be admin, and so Dragoneer conceded and gave his admin status back. Over two years have passed, and since then it's hard to say if Glaide has really done anything at all on the site.  Few people know he's admin.  He never joins the admin IRC, he rarely checks the admin forums, and he's a clear security risk. Dragoneer has hired him twice so far. This does seem to be entirely the fault of the administration above Glaide.
What if the pentagon has stored lost data of porn and yiff in it's data, has anyone over there saved about millions of porn data and art in it's computer drive? tell me more about the facts what they have in your opinions!

Freehaven

  • LOLS AND DONGS WHOLESALE
  • ***
  • Posts: 323
  • E-points: +12/-28
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #1 on: January 26, 2010, 06:15:31 pm »
Wow.  That's beyond stupid.  Man, 'Neer just can't get ANYONE competent on staff, can he?

rodox_video

  • ***
  • Posts: 486
  • E-points: +32/-8
  • HURF DURF DUH BLUH
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #2 on: January 26, 2010, 09:26:57 pm »
that would mean replacing himself
Zeriara is part of a series on Whores.

Pi

  • POOR IMPULSE CONTROL
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 614
  • E-points: +40/-10
  • <blink>yes hello</blink>
    • View Profile
    • Clan Spum userpage
Re: FA admins easily manipulated (who knew)
« Reply #3 on: January 27, 2010, 02:08:23 am »
I have still yet to understand why I haven't been given an admin position.

Their only rationale appears to be that that I would 'cause trouble'.
"we did farts.  now we do sperm.  we are cutting edge." — Theo DeRaadt

Freehaven

  • LOLS AND DONGS WHOLESALE
  • ***
  • Posts: 323
  • E-points: +12/-28
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #4 on: January 27, 2010, 05:15:52 am »
I have still yet to understand why I haven't been given an admin position.

Their only rationale appears to be that that I would 'cause trouble'.

I assume that's Pinkuhspeak for "you would actually do your job fairly and intelligently".

ProvincialTwit

  • Abuse Dept.
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 774
  • E-points: +72/-33
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #5 on: January 27, 2010, 12:57:17 pm »
Or at the very least, "take no bullshit and call people on it" which as we know is a cardinal sin among furries.

Ricky

  • not even worth the effort to insult
  • STOP POSTING
  • Posts: 17
  • E-points: +1/-65535
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #6 on: February 09, 2010, 06:58:14 pm »
Pi...  I think the problem is you don't relate well enough to furries.  Take that as a compliment.

Why would you even want to be an admin there?  They don't even pay, do they?
MOM FOR THE LAST TIME ITS NOT ANIMES ITS ANIME

Pi

  • POOR IMPULSE CONTROL
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 614
  • E-points: +40/-10
  • <blink>yes hello</blink>
    • View Profile
    • Clan Spum userpage
Re: FA admins easily manipulated (who knew)
« Reply #7 on: February 09, 2010, 07:08:42 pm »
"we did farts.  now we do sperm.  we are cutting edge." — Theo DeRaadt

LordNagetiere

  • ***
  • Posts: 390
  • E-points: +11/-16
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #8 on: February 09, 2010, 09:48:35 pm »
They don't even pay, do they?

You're a fucking moron, why would they? Why would any furry website like that consider an admin a paying position?
random gay furry art is broken , when will it be fixed ?

MetropolitanDonut

  • *
  • Posts: 72
  • E-points: +4/-1
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #9 on: February 10, 2010, 02:25:31 pm »
You're a fucking moron, why would they? Why would any furry website like that consider an admin a paying position?

Regardless of the site or its content, you can completely get away with the ego-inflation of "You are the Admin" to furries who still get by on instant noodles every night.  Why pay them if the shiny title is enough.

Fate

  • James Woods with a Handgun and a Hardon
  • *
  • Posts: 54
  • E-points: +9/-2
  • the fuck
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #10 on: March 18, 2010, 04:00:38 pm »
Regardless of the site or its content, you can completely get away with the ego-inflation of "You are the Admin" to furries who still get by on instant noodles every night.  Why pay them if the shiny title is enough.

Quote from: Peter Venkman
Keep the title, kid - It'll work hard for you.

loki

  • **
  • Posts: 125
  • E-points: +2/-2
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #11 on: April 04, 2010, 08:52:59 pm »
Didn't hear about this... lol.

As a side note, the XSS exploits in the submission preview tags are bad enough; gotta love how their entire log in system is based on session IDs stored in cookies. If you could convince an admin to look at a bad submission you could "become" them just by getting a copy of their login ID.

nrr

  • Sean Piche Fan Club
  • Cabalistic Fuckhead
  • *
  • Posts: 79
  • E-points: +7/-3
  • OMG SO CUTE ^__^
    • View Profile
    • lynxies :3
Re: FA admins easily manipulated (who knew)
« Reply #12 on: April 05, 2010, 06:51:20 pm »
gotta love how their entire log in system is based on session IDs stored in cookies
How would you handle sessions?
im glad the "I saw a furry IRL" thread is so good at bringing goons together

YOUR PARTICIPLES AREN'T THE ONLY THINGS DANGLING

loki

  • **
  • Posts: 125
  • E-points: +2/-2
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #13 on: April 06, 2010, 06:30:36 pm »
How would you handle sessions?

Well, I would at least have some way to regenerating session IDs so that I couldn't store someone's session ID cookie and come log in a week later after they do. Right now it only boots you out if you log in from a different computer (it regenerates the session ID) so basically as long as the person only uses one computer you can stay as them for a long time.

At the very least I would check the IP address of the person when they log in and make sure it hasn't changed - if it has, just make them log in again.

nrr

  • Sean Piche Fan Club
  • Cabalistic Fuckhead
  • *
  • Posts: 79
  • E-points: +7/-3
  • OMG SO CUTE ^__^
    • View Profile
    • lynxies :3
Re: FA admins easily manipulated (who knew)
« Reply #14 on: April 06, 2010, 07:02:11 pm »
Well, I would at least have some way to regenerating session IDs so that I couldn't store someone's session ID cookie and come log in a week later after they do. Right now it only boots you out if you log in from a different computer (it regenerates the session ID) so basically as long as the person only uses one computer you can stay as them for a long time.

At the very least I would check the IP address of the person when they log in and make sure it hasn't changed - if it has, just make them log in again.

When I implement session management, I tend to put down a few criteria for invalidating a session.  My sessions space is two-dimensional, so in order to snag someone's session, you need to snag their user ID as well.  Either way, I can't have external referers, expired session IDs, suspended user IDs, authentication tokens that don't match, or a number of other things.  Binding to the IP address is optional and off by default.

If I have an external referer, I do some redirect magic to kill that session and generate a new one, etc.  You should get the idea at this point.
im glad the "I saw a furry IRL" thread is so good at bringing goons together

YOUR PARTICIPLES AREN'T THE ONLY THINGS DANGLING

ProvincialTwit

  • Abuse Dept.
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 774
  • E-points: +72/-33
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #15 on: April 06, 2010, 07:17:15 pm »
Or just do the simple and sane thing and EXPIRE THE GODDAMNED SESSION after X minutes of inactivity.

nrr

  • Sean Piche Fan Club
  • Cabalistic Fuckhead
  • *
  • Posts: 79
  • E-points: +7/-3
  • OMG SO CUTE ^__^
    • View Profile
    • lynxies :3
Re: FA admins easily manipulated (who knew)
« Reply #16 on: April 06, 2010, 07:24:09 pm »
Or just do the simple and sane thing and EXPIRE THE GODDAMNED SESSION after X minutes of inactivity.

I find it annoying as hell when I see something like "Your session has expired due to inactivity." when I try to POST/GET something, thinking that my session is still active.  This fails for user convenience.

Yes, your method is sane and simple, but it potentially pisses users off.  That said, I still set sessions to expire within a week of inactivity, and that counter resets pretty regularly, after every few requests.
im glad the "I saw a furry IRL" thread is so good at bringing goons together

YOUR PARTICIPLES AREN'T THE ONLY THINGS DANGLING

ProvincialTwit

  • Abuse Dept.
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 774
  • E-points: +72/-33
    • View Profile
Re: FA admins easily manipulated (who knew)
« Reply #17 on: April 06, 2010, 07:45:27 pm »
Fair enough.  Point being that there is a balance to be struck between 'security' and 'user convenience'.   

Then again we are talking about a site that spent $16k on something most of us here could probably build for half the cost in half the time.

nrr

  • Sean Piche Fan Club
  • Cabalistic Fuckhead
  • *
  • Posts: 79
  • E-points: +7/-3
  • OMG SO CUTE ^__^
    • View Profile
    • lynxies :3
Re: FA admins easily manipulated (who knew)
« Reply #18 on: April 06, 2010, 08:17:36 pm »
Fair enough.  Point being that there is a balance to be struck between 'security' and 'user convenience'.

The neat thing is that I can have some semblance of both with my method, even if the redirect magic to regenerate the session token can be somewhat annoying for people on really, really latent connections like GPRS.


Then again we are talking about a site that spent $16k on something most of us here could probably build for half the cost in half the time.

Honestly, FA's architecture is so fucked up that the only sensible thing to do is to run everything on really nice (and also really expensive) machines.  If it were honestly up to me, most of their hardware would be el cheapo San Jose-based SuperMicro shit with maybe one super expensive (and super nice) database box.  Those SuperMicro boxes would be running something like MogileFS for asset storage.  There, done.  Problem solved.

I hate purchasing parts and assembling machines.  I've had enough of that jive, and I'm willing to pay the premium to have someone do it for me.  Fuck it.
im glad the "I saw a furry IRL" thread is so good at bringing goons together

YOUR PARTICIPLES AREN'T THE ONLY THINGS DANGLING