They cost 17 million now so I thought I'd buy lots and sell them for the huge profit margin, but I stayed more than 24 hours and the miniguns never replenished.
DEA7TH: forum
DEA7TH [90220] Level 80
- Forum posts (Torn's count)
- 150 observed
- Archived posts
- 28
- Threads started (archived)
- 2
Boards
From the 28 newest archived posts.
- General Discussion
- Questions & Answers
- Faction Discussion
- Trading Post
- Bugs & Issues
- Suggestions
Threads started
Most-liked posts
Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.
They cost 17 million now so I thought I'd buy lots and sell them for the huge profit margin, but I stayed more than 24 hours and the miniguns never replenished.
Edit: I already found a company, this thread is now dead.
I need to spend my job points on the special which reduces the bank time, so your rig must be 5-10 stars. After 3 days I'll quit the job, and I'll pay you $6 mil. You can hire me at $0 per day. My work stats are actually really good, I'm rank 334:
- Manual labour: 218,886
- Intelligence: 144,610
- Endurance: 119,248
That fee should be enough, but if you believe $2 mil per day is too low, feel free to offer me a higher price, which I'll accept if nobody offered me less.
I hope to find a company very soon, ideally today or tomorrow morning.
Edit: Some embarrassing typos.
You do have to escape in this case.
setCustomerData is a JS function, maybe I wasn't clear about that.
My code is printing this:
https://gist.github.com/anonymous/63b17e241ec99218caae
(this is printed from Ruby code and received at the browser)
The problem is that the customer data is unescaped, and fetched from the DB. One could easily spot this vulnerability by inspecting the source and then abuse it by inserting a record for a customer which will result in this:
https://gist.github.com/anonymous/8d87ccb725e77a30fe38
I'm procrastinating on fixing that because the fix will ruin my beautiful code :c
Recent archived posts
We could at least use a mixed formula which factors in both nerve spent and number of crimes done, although I'd rather suggest awarding one 10-nerve crime MORE than five 2-nerve crimes, rather than less.
Also this is a great opportunity to add usefulness to the crimes which people do only for the achievements, because they otherwise put you at risk for jailing (huge crime XP loss) which usually doesn't justify their award.
I haven't even had time to notice the update. IRL too busy.
But my life is awesome IMO, so no regrets here.
Price increased to $2 mil per day.
If anyone is wondering why I'm paying for that, it's because I'm going away from Torn and need to access my bank money before that. There will also be a goodbye thread in the faction forum.
Edit: I already found a company, this thread is now dead.
I need to spend my job points on the special which reduces the bank time, so your rig must be 5-10 stars. After 3 days I'll quit the job, and I'll pay you $6 mil. You can hire me at $0 per day. My work stats are actually really good, I'm rank 334:
- Manual labour: 218,886
- Intelligence: 144,610
- Endurance: 119,248
That fee should be enough, but if you believe $2 mil per day is too low, feel free to offer me a higher price, which I'll accept if nobody offered me less.
I hope to find a company very soon, ideally today or tomorrow morning.
Edit: Some embarrassing typos.
Yes, until I see all the messages. Love them.
You must be very patient then. Let's see if this can make you crack :p
Most of the time I morphed out, it was just to be a bait to waste enemy energy and distract from online faction-mates who still have energy. Muhahaha
I ranked number one in getting hospitalized. Yay!
Also Sticky probably hates me for... reasons :D
Btw nice to see the respect not going to waste. If we won, we would've gained nothing.
Sorry, it doesn't depend on me. I won't hit your faction, FWIW.
Can't understand 1/3-1/2 of the messages here. Torn is weird.
I can't use the game right now. Found this from Google, can't access anything. Not sure if this is a known bug, I haven't read Announcements or anything today.
This is the message:
File: /torncity/html/casino/lib/sources/mongodb.lib.php Line: 113 Exeption: The MongoCursor object has not been correctly initialized by its constructor
(also: MongoDB is cool! :P)
Yep, looks like someone really persistent is holding all miniguns. Strange that (s)he doesn't seem to be selling them yet, though. The current cheapest seller can't be the man.
Edit: accidental post trying to edit my previous one, please delete.
I also kept track of people online in case someone else had the same strategy, and kept mugging them - only low gains, which means that they didn't prepare to buy lots of miniguns ($3m each). There was nobody too hard for me to mug.
Also at some point the flowers had refreshed, but the miniguns didn't - or if they did, they were gone too fast - but following that, the market price didn't drop.
I'm almost sure that they're gone from Mexico? Unless the refresh sometimes "misses".
@cursed_phoenix: Good point.
(why can't I edit my post to include a quote?)
They cost 17 million now so I thought I'd buy lots and sell them for the huge profit margin, but I stayed more than 24 hours and the miniguns never replenished.
to_json sanitizes? Let's test.
2.2.2 :001 > data1 = "some customer data"
=> "some customer data"
2.2.2 :002 > data2 = "/* malicious entry this whole line */ "}); !malicious JS code here!; doNothingWithArg({"
=> "/* malicious entry this whole line */ "}); !malicious JS code here!; doNothingWithArg({"
2.2.2 :003 > dict = {a: data1, b: data1, c: data1, d: data2, e: data1}
=> {:a=>"some customer data", :b=>"some customer data", :c=>"some customer data", :d=>"/* malicious entry this whole line */ "}); !malicious JS code here!; doNothingWithArg({", :e=>"some customer data"}
2.2.2 :004 > puts dict.to_json
{"a":"some customer data","b":"some customer data","c":"some customer data","d":"/* malicious entry this whole line */ "}); !malicious JS code here!; doNothingWithArg({","e":"some customer data"}
And JS appears to treat the " as an (escaped) character, so it treats the whole statement as a string - to_json encloses each value in " " from which you cannot escape. Looks like I can keep my beautiful implementation after all! After sanitizing <> anyway.
Yeah I know how to fix it, but this is a XSS vulnerability I left so it was on topic :P
to_json is not sanitizing, only converting the format - it's a pure Ruby method. Sanitizing the whole thing ruins the JSON so I'll have to print the brackets and the sanitized parts manually. But it's so ugly that way :(
You do have to escape in this case.
setCustomerData is a JS function, maybe I wasn't clear about that.
My code is printing this:
https://gist.github.com/anonymous/63b17e241ec99218caae
(this is printed from Ruby code and received at the browser)
The problem is that the customer data is unescaped, and fetched from the DB. One could easily spot this vulnerability by inspecting the source and then abuse it by inserting a record for a customer which will result in this:
https://gist.github.com/anonymous/8d87ccb725e77a30fe38
I'm procrastinating on fixing that because the fix will ruin my beautiful code :c
@Tom: I'm pleasantly surprised to see that we can be polite :) I had thought the whole point was to be hostile - glad to be wrong.
IMO PHP is quite bad and I did suggest that, but it's not useful discussion. However if the problem is really JS injection rather than CSRF then I don't think I can help - one of my applications (in development) still has this vulnerability. In this part:
<>
Actually I could just print it row by row and escape the parts which come from the DB.
Edit: Torn just ate all my code! Here it is anyway: https://gist.github.com/anonymous/c16e955ceb1001289aa0
Huh, you're right - XSS was the thing with the malicious JS from your own DB. The story sounded like CSRF though, and I could login via CURL, passing only player and password, no tokens - not useful for an attacker, but clearly they don't do CSRF by default.
I know what is PHP, my point is that I only know they're using PHP, not which framework. Anyway, what's your deal with trying to make others look stupid? I don't get it. When people get negative conditioning in response to trying to help, they will be less likely to help next time. You could have phrased your criticism politely.
I'm having that right now with editing my post. Maybe because I used code formatting? But clear formatting doesn't fix it.
Here is the post in question. The version I could not submit had the code inside, and didn't have the gisthub link or the comment about how I couldn't edit, everything else was identical.
http://www.torn.com/forums.php#!p=threads&f=2&t=15956205&b=0&a=0&start=80