Bitcoin Forum

Other => Meta => Topic started by: angel55 on June 26, 2018, 01:34:07 PM



Title: How does this account have an avatar?
Post by: angel55 on June 26, 2018, 01:34:07 PM
This account is only member level?

https://bitcointalk.org/index.php?action=profile;u=130334


Title: Re: How does this account have an avatar?
Post by: TryNinja on June 26, 2018, 01:41:44 PM
You could use an avatar at any rank back in the old days.

OP added his avatar when it was possible for him.


Title: Re: How does this account have an avatar?
Post by: TheQuin on June 26, 2018, 02:03:41 PM
You could use an avatar at any rank back in the old days.

OP added his avatar when it was possible for him.

That was before the 2013 forum hack. That also means it is impossible for them to remove that avatar. In this case, that means they are most likely stuck with someone else's photo.

Either that or they took a few years away from the forum to learn Czech.

https://i.snag.gy/WaPVM3.jpg


Title: Re: How does this account have an avatar?
Post by: luckybar on June 26, 2018, 05:08:51 PM
Wow he speaks czech, english, and chinese, impressive........

But seriously it would be nice to allow members to wear avatars again.


Title: Re: How does this account have an avatar?
Post by: jackg on June 26, 2018, 06:45:06 PM
You could use an avatar at any rank back in the old days.

OP added his avatar when it was possible for him.

That was before the 2013 forum hack. That also means it is impossible for them to remove that avatar. In this case, that means they are most likely stuck with someone else's photo.
I think a PM to theymos/Cyrus or probably a global mod would allow for the image to be removed.

Why did the 2013 hack stop avatars being removed?


Title: Re: How does this account have an avatar?
Post by: mdayonliner on June 26, 2018, 06:50:21 PM
Why did the 2013 hack stop avatars being removed?
I guess TheQuin meant in general by the member himself.


Title: Re: How does this account have an avatar?
Post by: TheQuin on June 27, 2018, 04:45:03 AM
Why did the 2013 hack stop avatars being removed?

From when it happened:

It was initially suspected by many that the attack was done by exploiting a flaw in SMF which allows you to upload any file to the user avatars directory, and then using a misconfiguration in nginx to execute this file as a PHP script. However, this attack method seems impossible if PHP's security.limit_extensions is set.

It was disabled while they were still investigating the hack and then just never turned back on. Removing avatars is done from the same page as adding one:

Quote
To remove your avatar, submit this form without choosing any file to upload.

If you are not a Full Member or above you can't get to that page. I think it is just how SMF works rather than deliberate. ie the permission setting to add or remove an avatar is the same thing so you can't grant permission to one without the other.


Title: Re: How does this account have an avatar?
Post by: Silent26 on June 27, 2018, 07:15:39 AM
A little off-topic. I've found that this account unpack (https://bitcointalk.org/index.php?action=profile;u=130334) has two possible alt accounts which is AltT25 (https://bitcointalk.org/index.php?action=profile;u=1725267) and Nafta012 (https://bitcointalk.org/index.php?action=profile;u=1413379). I found out that these two accounts are using unpack's twitter link which is https://twitter.com/altcoinsINF

Should I make a report for this now?


Title: Re: How does this account have an avatar?
Post by: jackg on June 27, 2018, 03:23:45 PM
Why did the 2013 hack stop avatars being removed?

From when it happened:

It was initially suspected by many that the attack was done by exploiting a flaw in SMF which allows you to upload any file to the user avatars directory, and then using a misconfiguration in nginx to execute this file as a PHP script. However, this attack method seems impossible if PHP's security.limit_extensions is set.

It was disabled while they were still investigating the hack and then just never turned back on. Removing avatars is done from the same page as adding one:

Quote
To remove your avatar, submit this form without choosing any file to upload.

If you are not a Full Member or above you can't get to that page. I think it is just how SMF works rather than deliberate. ie the permission setting to add or remove an avatar is the same thing so you can't grant permission to one without the other.

Ahhh so that was why it was done. Just due to SMF being slightly temperamental.
& admins can change sigs if they wish so the avatars can be changed.


Title: Re: How does this account have an avatar?
Post by: Thirdspace on June 27, 2018, 11:13:53 PM
A little off-topic. I've found that this account unpack (https://bitcointalk.org/index.php?action=profile;u=130334) has two possible alt accounts which is AltT25 (https://bitcointalk.org/index.php?action=profile;u=1725267) and Nafta012 (https://bitcointalk.org/index.php?action=profile;u=1413379). I found out that these two accounts are using unpack's twitter link which is https://twitter.com/altcoinsINF

Should I make a report for this now?

having multiple accounts is not against forum rules
but you can report to the campaign manager if they joined in one bounty campaign that prohibits multi accounts
and you can also expose them by posting here Known Alts of any-one - A User Generated List Mk III (2018 Q2) (https://bitcointalk.org/index.php?topic=2544574.0)

Either that or they took a few years away from the forum to learn Czech.
possibly hacked or bought account? I'm pretty sure soon or later that account would get locked ;)


Title: Re: How does this account have an avatar?
Post by: Silent26 on June 28, 2018, 02:26:51 AM
having multiple accounts is not against forum rules
but you can report to the campaign manager if they joined in one bounty campaign that prohibits multi accounts
and you can also expose them by posting here Known Alts of any-one - A User Generated List Mk III (2018 Q2) (https://bitcointalk.org/index.php?topic=2544574.0)
I went through these two account's posts (AltT25 and Nafta012) and found out that they both joined with a same twitter bounty back in January, and also there are 3 transactions between their eth addresses. AltT25 sent about 0.733 ether to Nafta012 and further investigation, there are still another account involved.

unpack seems like he/she is not joining any bounty that's why it is vague that he is the owner of these two but the thing is, these two accounts used unpack's twitter for about several times. So, does it means he is involved too?

By the way, AltT25 and Nafta012 seems like haven't been active recently since April.

What do you think? Should I make report for this now?