Bitcoin Forum
November 15, 2024, 06:37:33 PM *
News: Check out the artwork 1Dq created to commemorate this forum's 15th anniversary
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 »  All
  Print  
Author Topic: Time to bring back avatars  (Read 3036 times)
BigMac
Legendary
*
Offline Offline

Activity: 896
Merit: 1000



View Profile
June 05, 2014, 01:27:52 AM
 #21

And why hasn't the forum been upgraded and fixed yet. Are the 1000s of Bitcoin donated to Theymos not enough to cover it?

The new forum software costs 1 mil USD (~1500 btc), but no worries, the forum has way more than that. Smiley

jeffersonairplane
Legendary
*
Offline Offline

Activity: 1522
Merit: 1000


www.bitkong.com


View Profile
June 05, 2014, 02:24:24 AM
 #22

I would love avatars to come back. Don't see why they were taken away in the first place.

BTCitcointalk
.    ██████████████████████████████████
                                                                 ██
                                                               ███   ██
                                                      ██      ███  ███
                                                     ███     ██  ███  ██
    ▄▄████▄▄    █▌                                         ███  ██  ██
  ██▀       ▀▀  █▌                                   ▀▀   ██▌███  ███ ██
▄█              █▌  ▄▄▄▄        ▄▄▄▄▄  ▄▄   ▄   ▄▄▄█▄████████ ████   
█▌              ███▀.   ██    ██     ▀███   ███▀
   ████████████████      ▐█
█               ██       █   ██        ██   ██
     █████████▌██████       ▐█
█▌              █▌       █▌  █         ██   ██
      ██████████▀   █       ▐█
 █▄             █▌       █▌
█████████████████████████████████▌     █       ██
  ▀██▄     ▄██  ██
████████▌██████████████████████████████████     ██▄   ▄███
     ▀████▀▀████████████████████▀▀▀▀▀██████               ██▄▀▀██    ▀▀▀  ██
   ███▀▀▄▄▄█████████████▀▀▀▀▀▀▀▀▀▀                           ██████▄     ██
 ███▄▄██████████▀                                                 ▀█████▀▀
                                                                        ███
.

█████████████████████████████
Program

❤️
Give Hope To Everyone
━━━━━━━» $1 Is A Big Thing For Them

❤️
.
Swordsoffreedom
Legendary
*
Online Online

Activity: 2954
Merit: 1135


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
June 05, 2014, 02:27:31 AM
 #23

I would love avatars to come back. Don't see why they were taken away in the first place.

It was because bitcointalk got hacked back in 2013 and they needed to disable them

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
BigMac
Legendary
*
Offline Offline

Activity: 896
Merit: 1000



View Profile
June 05, 2014, 02:42:02 AM
 #24

I would love avatars to come back. Don't see why they were taken away in the first place.

It was because bitcointalk got hacked back in 2013 and they needed to disable them


For those interested, you can refer to the thread https://bitcointalk.org/index.php?topic=306878.0

On October 3, it was discovered that an attacker inserted some JavaScript into forum pages. The forum was shut down soon afterward so that the issue could be investigated carefully. After investigation, I determined that the attacker most likely had the ability to execute arbitrary PHP code. Therefore, the attacker probably could have accessed personal messages, email addresses, and password hashes, though it is unknown whether he actually did so.

Passwords were hashed very strongly. Each password is hashed with 7500 rounds of sha256crypt and a 12-byte random salt (per password). Each password would need to be individually attacked in order to retrieve the password. However, even fairly strong passwords may be crackable after a long period of time, and weak passwords (especially ones composed of only a few dictionary words) may still be cracked quickly, so it is recommended that you change your password here and anywhere else you used the password.

The attacker may have modified posts, PMs, signatures, and registered Bitcoin addresses. It isn't practical for me to check all of these things for everyone, so you should double-check your own stuff and report any irregularities to me.

How the attack was done

I believe that this is how the attack was done: After the 2011 hack of the forum, the attacker inserted some backdoors. These were removed by Mark Karpelles in his post-hack code audit, but a short time later, the attacker used the password hashes he obtained from the database in order to take control of an admin account and insert the backdoors back in. (There is a flaw in stock SMF allowing you to login as someone using only their password hash. No bruteforcing is required. This was fixed on this forum when the password system was overhauled over a year ago.) The backdoors were in obscure locations, so they weren't noticed until I did a complete code audit yesterday.

After I found the backdoors, I saw that someone (presumably the attacker) independently posted about his attack method with matching details. So it seems very likely that this was the attack method.

Because the backdoors were first planted in late 2011, the database could have been secretly accessed any time since then.

It was initially suspected by many that the attack was done by exploiting a flaw in SMF which allows you to upload any file to the user avatars directory, and then using a misconfiguration in nginx to execute this file as a PHP script. However, this attack method seems impossible if PHP's security.limit_extensions is set.

Swordsoffreedom
Legendary
*
Online Online

Activity: 2954
Merit: 1135


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
June 05, 2014, 02:47:19 AM
Last edit: June 05, 2014, 09:17:40 AM by Swordsoffreedom
 #25

It was because bitcointalk got hacked back in 2013 and they needed to disable them

For those interested, you can refer to the thread https://bitcointalk.org/index.php?topic=306878.0


Good point will contribute a video of it in practice as well since a picture says a 1000 words and a video is a play by play Smiley
http://www.youtube.com/watch?v=LKrOHAfMdxI

That said did Theymos finally review the 1XX script the hack was way back in 2013 so there should have been sufficient time to see if the problem was with avatars.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
SgtMoth
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1004


buy silver!


View Profile
June 05, 2014, 02:52:06 AM
 #26

whats an avatar?
jonald_fyookball
Legendary
*
Offline Offline

Activity: 1302
Merit: 1008


Core dev leaves me neg feedback #abuse #political


View Profile
June 05, 2014, 03:31:34 AM
 #27

Nginx ehh.. What's wrong with apache?

BigMac
Legendary
*
Offline Offline

Activity: 896
Merit: 1000



View Profile
June 05, 2014, 04:05:40 AM
 #28

It was because bitcointalk got hacked back in 2013 and they needed to disable them
For those interested, you can refer to the thread https://bitcointalk.org/index.php?topic=306878.0
Good point will contribute a video of it in practice as well since a picture says a 1000 words and a video is a play by play Smiley
http://www.youtube.com/watch?v=LKrOHAfMdxI

That said did Theymos finally review the 1XX script the hack was way back in 2013 so there should have been sufficient time to see if the problem was with avatars.

It seems your quotes didn't work very well. Wink

CEG5952
Hero Member
*****
Offline Offline

Activity: 658
Merit: 500

Buy and sell bitcoins,


View Profile
June 05, 2014, 06:45:23 AM
 #29

I'd love for avatars to come back. LOL, I'm stuck with this guy. I just randomly picked one when I joined. If I knew I was gonna stick around, I probably would have chosen a better one... Undecided

Swordsoffreedom
Legendary
*
Online Online

Activity: 2954
Merit: 1135


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
June 05, 2014, 09:17:06 AM
 #30


It seems your quotes didn't work very well. Wink

Sometimes I try to get rid of the quote walls or adjust it to topic and miss one sorry about that and edited  Grin.
I am not sure if suggesting a pruning method to include certain quotes only would be a software improvement or just being lazy lol.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
gagalady
Legendary
*
Offline Offline

Activity: 938
Merit: 1000


View Profile
June 05, 2014, 03:36:20 PM
 #31

I would also like to get avatars back and why they were disabled , for what reason?
Yuki1988
Hero Member
*****
Offline Offline

Activity: 614
Merit: 500



View Profile
June 05, 2014, 03:59:32 PM
 #32

I would also like to get avatars back and why they were disabled , for what reason?


Read a few posts up there, and you will see.

I would love avatars to come back. Don't see why they were taken away in the first place.

It was because bitcointalk got hacked back in 2013 and they needed to disable them


For those interested, you can refer to the thread https://bitcointalk.org/index.php?topic=306878.0

On October 3, it was discovered that an attacker inserted some JavaScript into forum pages. The forum was shut down soon afterward so that the issue could be investigated carefully. After investigation, I determined that the attacker most likely had the ability to execute arbitrary PHP code. Therefore, the attacker probably could have accessed personal messages, email addresses, and password hashes, though it is unknown whether he actually did so.

Passwords were hashed very strongly. Each password is hashed with 7500 rounds of sha256crypt and a 12-byte random salt (per password). Each password would need to be individually attacked in order to retrieve the password. However, even fairly strong passwords may be crackable after a long period of time, and weak passwords (especially ones composed of only a few dictionary words) may still be cracked quickly, so it is recommended that you change your password here and anywhere else you used the password.

The attacker may have modified posts, PMs, signatures, and registered Bitcoin addresses. It isn't practical for me to check all of these things for everyone, so you should double-check your own stuff and report any irregularities to me.

How the attack was done

I believe that this is how the attack was done: After the 2011 hack of the forum, the attacker inserted some backdoors. These were removed by Mark Karpelles in his post-hack code audit, but a short time later, the attacker used the password hashes he obtained from the database in order to take control of an admin account and insert the backdoors back in. (There is a flaw in stock SMF allowing you to login as someone using only their password hash. No bruteforcing is required. This was fixed on this forum when the password system was overhauled over a year ago.) The backdoors were in obscure locations, so they weren't noticed until I did a complete code audit yesterday.

After I found the backdoors, I saw that someone (presumably the attacker) independently posted about his attack method with matching details. So it seems very likely that this was the attack method.

Because the backdoors were first planted in late 2011, the database could have been secretly accessed any time since then.

It was initially suspected by many that the attack was done by exploiting a flaw in SMF which allows you to upload any file to the user avatars directory, and then using a misconfiguration in nginx to execute this file as a PHP script. However, this attack method seems impossible if PHP's security.limit_extensions is set.

ampere9765
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250



View Profile
June 05, 2014, 09:42:11 PM
 #33

Okay, so we just need to come up with a million bucks for the forum, and then I am no longer stuck being Bruce Willis? Sounds good to me. Let's get on that! Smiley
hilariousandco
Global Moderator
Legendary
*
Online Online

Activity: 3990
Merit: 2717


Join the world-leading crypto sportsbook NOW!


View Profile
June 05, 2014, 09:54:13 PM
 #34

Theymos has previously stated that he will remove avatars for people who don't want theirs anymore but won't change them. Pm him if you want but I'd just keep it for now.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Cryptopher
Legendary
*
Offline Offline

Activity: 1789
Merit: 1008


Keep it dense, yeah?


View Profile
June 05, 2014, 10:17:41 PM
 #35

and also return "move topic" and "make thread self moderated" to the options please.  No reason to remove them, not having them in there just creates more work for mods.

The move topic is still there, in the bottom left when viewing your topic. You can make a thread self-moderated at topic creation time under additional options, but I don't believe that you can subsequently change this.

I would love to see the avatar option return - I know that it is in the new forum plans, but it would be nice if they were activated on here again. They stopped allowing avatars by the time I had joined the forum.

Sign up to Revolut and do the Crypto Quiz to earn $15/£14 in DOT
oli123123
Legendary
*
Offline Offline

Activity: 1445
Merit: 1000



View Profile
June 07, 2014, 05:46:30 PM
 #36

Guys please stop creating threads like this, you won't be able to change your avatar until the forum software upgrade.
Yuki1988
Hero Member
*****
Offline Offline

Activity: 614
Merit: 500



View Profile
June 07, 2014, 05:51:04 PM
 #37

Guys please stop creating threads like this, you won't be able to change your avatar until the forum software upgrade.

This thread is not new (created in Apr), but it gets bumped...

Cryptopher
Legendary
*
Offline Offline

Activity: 1789
Merit: 1008


Keep it dense, yeah?


View Profile
June 07, 2014, 05:55:09 PM
 #38

Guys please stop creating threads like this, you won't be able to change your avatar until the forum software upgrade.

This thread is not new (created in Apr), but it gets bumped...

By new I think that he means that it was decided before then that we won't have custom avatars until at least the forum software upgrade.

Sign up to Revolut and do the Crypto Quiz to earn $15/£14 in DOT
oli123123
Legendary
*
Offline Offline

Activity: 1445
Merit: 1000



View Profile
June 07, 2014, 10:50:41 PM
 #39

Guys please stop creating threads like this, you won't be able to change your avatar until the forum software upgrade.

This thread is not new (created in Apr), but it gets bumped...
Oh, my bad, i thought it was a new thread, i've seen many avatar threads in the meta forum recently.
AlPutino
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
June 08, 2014, 06:23:06 AM
 #40

yes please!!!!11 I would like to constantly see the flawless image of alPutino there.
Pages: « 1 [2] 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!