Help - Search - Members - Calendar
Full Version: Unauthorised interference with my posts
HTMLHelp Forums > Administrative > Feedback and Assistance
Brian Chandler
I just made a post which the forum software mangled. I wrote (spelling out): left-parenthesis t m right-parenthesis. The forum software changed this. I do not like having what I write buggered up by crappy software, so is there any chance you could switch this particular piece of stupidity off?

In this case it didn't matter too much, but I would like to be free to write using conventional expressions, which includes all sorts of things the peanut-brain authors of this rubbish just forgot to think of. If I write a mathematical or pseudomathematical expression e=mc^2, whatever, I don't really want it messed up.

Thank you.
Ephraim F. Moya
I think you ought to change your handle to Key-Shoat (Quixote).
java script:emoticon(':D', 'smid_4')
:Djava script:emoticon(':angry:', 'smid_7')
:angry:java script:emoticon(':lol:', 'smid_13')
:lol:java script:emoticon(':angry2:', 'smid_6')
:angry2:java script:emoticon(';)', 'smid_23')
;)java script:emoticon(':wub:', 'smid_22')
wub.gif
Brian Chandler
QUOTE(Ephraim F. Moya @ Nov 4 2006, 12:51 AM) *

I think you ought to change your handle to Key-Shoat (Quixote).
java script:emoticon(':D', 'smid_4')
:Djava script:emoticon(':angry:', 'smid_7')
:angry:java script:emoticon(':lol:', 'smid_13')
:lol:java script:emoticon(':angry2:', 'smid_6')
:angry2:java script:emoticon(';)', 'smid_23')
;)java script:emoticon(':wub:', 'smid_22')
wub.gif


What is this :xxx:java script:... stuff?

Anyway, I don't have a 'handle'. I'm me.

tongue.gif huh.gif sleep.gif rolleyes.gif
Guest
"What is this :xxx:java script:... stuff?"

Dunno. I just clicked the little symbol and that's what I got.
the windmill
You boys should stick to the plain text lo-fi version of this board, and leave the smilies to the experts. wink.gif
John Pozadzides
QUOTE(Brian Chandler @ Nov 2 2006, 03:37 AM) *
I just made a post which the forum software mangled. I wrote (spelling out): left-parenthesis t m right-parenthesis. The forum software changed this. I do not like having what I write buggered up by crappy software, so is there any chance you could switch this particular piece of stupidity off?

Brian,

At the moment I can't even find where to disable this, so I'll have to do some digging. I think its buried in the code. Since we don't really need to worry about TradeMark stamping things on the site I'll disable it whenever I find it.

John
JamieHarrop
Old thread, I know.

I just had this happen to me. I typed Javascript (I typed it as one word) and it split it in to two words.

It was in this thread: http://forums.htmlhelp.com/index.php?showtopic=1449&hl=

It's strange that it hasn't split the word in to two in this thread.
Darin McGrew
Typing JavaScript or javascript isn't the problem. Typing j avascript: (or J avaScript: or J aVaScRiPt: or ...) is the problem.

I added a space in my examples above. Without a space, they all get converted to the same thing: Typing java script: (or java script: or java script: or ...) is the problem.
jimlongo
Are you saying it's because of the colon?
pandy
QUOTE(jimlongo @ Dec 7 2006, 11:40 PM) *

Are you saying it's because of the colon?

Do you have a problem with yours? laugh.gif


JavaScript:alert('Boo!'); cool.gif
JamieHarrop
QUOTE
Are you saying it's because of the colon?


It seems that is what Darin is saying Jim.

I still not sure why Invision does this though.
jimlongo
Funny, but since you're asking . . . the colonoscopy I had this afternoon was negative smile.gif
Darin McGrew
TMI!
pandy
If you are not joking jimlongo, I'm glad for you. Well, I'm in a pretty good mood in case you were joking too. smile.gif
Christian J
QUOTE(pandy @ Dec 7 2006, 11:44 PM) *

java script:alert('Boo!'); cool.gif

How did you make that work in your post, with entities? huh.gif

java script:alert('Boo!');
pandy
QUOTE(Christian J @ Dec 8 2006, 01:16 AM) *

How did you make that work in your post, with entities? huh.gif

By putting my leet skillz to work, obviously. cool.gif tongue.gif
jimlongo
QUOTE(pandy @ Dec 7 2006, 06:49 PM) *

If you are not joking jimlongo, I'm glad for you.

thanks, it's a routine screening nowadays . . . I urge anyone born before the Cuban missile crisis to look into it. It's not so bad and in some ways an interesting experience.

QUOTE
Well, I'm in a pretty good mood in case you were joking too. smile.gif

then I'm happy with both results!



Christian J
QUOTE(pandy @ Dec 8 2006, 01:51 AM) *

QUOTE(Christian J @ Dec 8 2006, 01:16 AM) *

How did you make that work in your post, with entities? huh.gif

By putting my leet skillz to work, obviously. cool.gif tongue.gif

If you don't tell I will pout. ninja.gif
jimlongo
QUOTE(Darin McGrew @ Dec 7 2006, 06:41 PM) *

TMI!


I had to go down about 20 references to find the TMI you were talking about.
John Pozadzides
QUOTE(Christian J @ Dec 8 2006, 09:18 AM) *

QUOTE(pandy @ Dec 8 2006, 01:51 AM) *

QUOTE(Christian J @ Dec 8 2006, 01:16 AM) *

How did you make that work in your post, with entities? huh.gif

By putting my leet skillz to work, obviously. cool.gif tongue.gif

If you don't tell I will pout. ninja.gif

Entities don't work. I seriously have no idea how Pandy pulled that off. People have been trying to do that with IPB forever.

You have got to tell us how you pulled that one off!

John
pandy
QUOTE(Christian J @ Dec 8 2006, 04:18 PM) *

If you don't tell I will pout. ninja.gif

You are cute when you pout. wub.gif



QUOTE(John Pozadzides @ Dec 8 2006, 09:28 PM) *


Entities don't work. I seriously have no idea how Pandy pulled that off. People have been trying to do that with IPB forever.

You have got to tell us how you pulled that one off!


No. I want to see you pout too first. tongue.gif
Christian J
QUOTE(John Pozadzides @ Dec 8 2006, 09:28 PM) *

Entities don't work. I seriously have no idea how Pandy pulled that off. People have been trying to do that with IPB forever.

A simple googling turned up the following:

javascript:

If you look in the BBCode you can see how I did it, but pandy seems to use some other trick that makes the BBCode appear normal.

BTW feel free to edit this post if you don't want everyone to know. tongue.gif
pandy
Can you put it in a script box? IPB Image

CODE
javascript:alert('Klutz!');
John Pozadzides
QUOTE(pandy @ Dec 8 2006, 04:52 PM) *

QUOTE(John Pozadzides @ Dec 8 2006, 09:28 PM) *
You have got to tell us how you pulled that one off!

No. I want to see you pout too first. tongue.gif

Ok. I'm pouting... see? Now, tell us how you did it!
Click to view attachment


QUOTE(Christian J @ Dec 16 2006, 11:29 AM) *
A simple googling turned up the following:

javascript:

Hmm... You say "simple" but I don't know how you found that. I know a lot of people, including me, that looked for it in the past but couldn't find it.

But like you said, that isn't how Pandy is doing it.
QUOTE
java script:alert('Boo!');

Dammit!

John
pandy
I knew you would give up if I waited long enough. laugh.gif That mug's so cute I just have to tell you. wub.gif

Ready? Here goes!
CODE
javascript: alert('Boo!');

CODE
javascript: alert('Boo!');

You can do it with any or all characters in 'javascript:'. IPB Image

It isn't my fault you guys listen to hearsay and don't test for yourselves! cool.gif IPB Image
Christian J
QUOTE(John Pozadzides @ Dec 27 2006, 04:20 AM) *

QUOTE(Christian J @ Dec 16 2006, 11:29 AM) *
A simple googling turned up the following:

javascript:

Hmm... You say "simple" but I don't know how you found that. I know a lot of people, including me, that looked for it in the past but couldn't find it.

IIRC I searched for ways to circumvent the bad word censor...

BTW here's a mod for phpBB, maybe IPB has something similar though the mod appears to work only on empty BBCode tags (and not when you put content inside them like I did).
Christian J
QUOTE(pandy @ Dec 27 2006, 05:05 AM) *

It isn't my fault you guys listen to hearsay and don't test for yourselves! cool.gif IPB Image

I did test &!

Is this the same thing: http://secunia.com/advisories/20772 ?
pandy
QUOTE(Christian J @ Dec 27 2006, 09:45 PM) *

I did test &!

Kids nowadays... Give up when it doesn't work on the first try. Tsss, tsss, tsss. tongue.gif

QUOTE

Is this the same thing: http://secunia.com/advisories/20772 ?

Dont know. They say hex and I used decimal. Hex doesn't seem to work.

CODE
javascript: alert('Buu!');
John Pozadzides
QUOTE(pandy @ Dec 27 2006, 08:45 PM) *

QUOTE(Christian J @ Dec 27 2006, 09:45 PM) *

I did test &!

Kids nowadays... Give up when it doesn't work on the first try. Tsss, tsss, tsss. tongue.gif

I swear I tested that also, multiple times!

QUOTE(pandy @ Dec 27 2006, 08:45 PM) *

QUOTE(Christian J @ Dec 27 2006, 09:45 PM) *

Is this the same thing: http://secunia.com/advisories/20772 ?

Dont know. They say hex and I used decimal. Hex doesn't seem to work.

CODE
java script: alert('Buu!');


I've already patched for that issue...

John
John Pozadzides
QUOTE(pandy @ Dec 26 2006, 10:05 PM) *

CODE
javascript: alert('Boo!');

CODE
java script: alert('Boo!');


Interesting. I just also learned that if you use the & trick, the first time you preview the post it switches it to the regular character. Then if you post it goes back to being broken.

Basically this only works if you do NOT preview your post before taking it live.

John
pandy
Yes, lots of boards do that. Messes quoting up, that.

Actually, it was pure luck I found this out. I use a script in my text editor to convert characters to entities. When I wrote it I chose dec since that's supposed to be most widely supported. So when I wanted to try "javascript:" with entities, decimal it was. Had my script happened to do hex, maybe I too had given up there. tongue.gif

Wonder if it is a vulnerability BTW. If it is it shall be known as "The WDG Hole". cool.gif

Christian J
Doesn't seem to work in links, but not sure why not (since the "javascript" part is still intact):

[url=javascript: alert('Boo!');]foo[/url]
pandy
It's because of the space. But the board adds 'http' if it isn't present.

TESTING
rahul286
QUOTE(pandy @ Dec 29 2006, 12:38 PM) *

Yes, lots of boards do that. Messes quoting up, that.

Actually, it was pure luck I found this out. I use a script in my text editor to convert characters to entities. When I wrote it I chose dec since that's supposed to be most widely supported. So when I wanted to try "java script:" with entities, decimal it was. Had my script happened to do hex, maybe I too had given up there. tongue.gif

Wonder if it is a vulnerability BTW. If it is it shall be known as "The WDG Hole". cool.gif


Hello pandy, first thanx for :
Can u tel me in details how do u use a script in text editor! Does it work for all members???
Actually I am running an invision board and there is completely dedicated thread for javascript&#58
So I would really appreciate ur help!
Thanks in advance! smile.gif
pandy
No, you can't do it with any text editor. The one I use, Notetab, is programmable using its own scripting language. I like the way the sripts are evoked. Look at this picture http://notetab.com/screen01.html . What you see in the left window is a library with scripts. Each item in the list is a script. In this case it's just text macros that inserts CSS stuff in the document, but they can be a lot more advanced than that, process text, documents, disk files. You can have as many libraries as you want with many scripts in each.
rahul286
So is there any other solution??
something like BBCode or MODS...
wel I have access to PHP source code of IPB, so I can modify any file!
And thanks for replying so soon! smile.gif
pandy
I don't understand what you want to do. Can't you just use #58 if that works?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.