You are currently looking at Flamebate, our community forums. Players can discuss the game here, strategize, and role play as their characters.
You need to be logged in to post and to see the uncensored versions of these forums.
Update on the Haxxploitation E-Peen(tm) | |||||||
---|---|---|---|---|---|---|---|
|
A lot of people are interested in the coveted Haxploitation E-Peen™.
The E-Peen™ exists as a way for us to thank people for identifying exploits on the site (gameplay/security/etc) and reporting them to us privately so they can be fixed.
In other words, if you find something broken, then go crazy posting it on Flamebate or IDC, upsetting the economy and crashing the game to a halt, you won’t get the E-Peen™.
Some people seem to think we have made exceptions to this rule. However, to the best of my knowledge we have not. Sometimes people who announce exploits publically get the E-Peen™ for other reasons, but I have been giving it out this way for quite some time.
Sometimes, an adept player will report more than one exploit, even after they have received the E-Peen™. If they have alts, we’ll let them give the E-Peen™ to another alt. Still, as you can imagine this doesn’t encourage people to keep finding and telling us about exploits.
So, my new policy is to give 30 BP per identified/fixed exploit to any player who already has the E-Peen™. This is to encourage continued good behavior.
Thanks for all the help so far guys. Every time we fix a hole it makes the game better for everyone else! |
||||||
Posted On: 02/04/2009 12:16PM | View Evil Trout's Profile | # | ||||||
|
Evil Trout Posted:
Retroactive? Log in to see images!
|
||||||
Posted On: 02/04/2009 12:17PM | View MC Banhammer's Profile | # | ||||||
|
I found something I think might be worth it. I TM’d you about it. Lemme know pls! |
||||||
Posted On: 02/04/2009 12:18PM | View Fortunato's Profile | # | ||||||
|
Fortunato Posted:
I confirmed yours this morning. A fix is coming and you’ll get the E-Peen™ when it goes live Log in to see images!
MC Banhammer Posted: |
||||||
Posted On: 02/04/2009 12:21PM | View Evil Trout's Profile | # | ||||||
|
Evil Trout Posted: |
||||||
Posted On: 02/04/2009 12:22PM | View Montressor's Profile | # | ||||||
|
If the goal is to encourage the finding of hacks, would it be worth publicizing the ones which were deserving of the peen, in order to “jump-start” ideas on how to find them? Or are you too worried that would lead to abuse? |
||||||
Posted On: 02/04/2009 12:28PM | View MC Banhammer's Profile | # | ||||||
|
Ok ladies time to haxx! Log in to see images! |
||||||
Posted On: 02/04/2009 12:28PM | View Longhorn555's Profile | # | ||||||
|
Your databases arent SQL injections vulnerable Log in to see images! |
||||||
Posted On: 02/04/2009 12:29PM | View Longhorn555's Profile | # | ||||||
|
MC Banhammer Posted:
Yeah it’s a slippery slope.
The most common exploits tend to be CSRF based. In other words, links to the site that will change your data that will work just as pbuming a link around.
We’ve never had a SQL injection exploit, probably because we use ActiveRecord and rarely write out manual SQL. |
||||||
Posted On: 02/04/2009 12:43PM | View Evil Trout's Profile | # | ||||||
|
MC Banhammer Posted: |
||||||
Posted On: 02/04/2009 12:56PM | View Acid Flux's Profile | # | ||||||
|
Acid Flux Posted:
Generally if more than one person identifies an exploit, the first person to report it gets it. |
||||||
Posted On: 02/04/2009 1:14PM | View Evil Trout's Profile | # | ||||||
|
Is there any way for non-malicious-non-hacker players like me to ever get the peen?
And also, if we report serious bugs when a new update launches, that doesn’t count, correct? |
||||||
Posted On: 02/04/2009 1:17PM | View Shii's Profile | # | ||||||
|
Can I start a thread detailing how I got it?
Log in to see images! |
||||||
Posted On: 02/04/2009 1:19PM | View Fortunato's Profile | # | ||||||
|
I reported when I got negative PP. Does that make me eligible for this e-peen or am I just being a huge n00b for asking? |
||||||
Posted On: 02/04/2009 1:22PM | View LRFLEW's Profile | # | ||||||
|
*shakes fist at Fortunato* Shii edited this message on 02/04/2009 1:23PM |
||||||
Posted On: 02/04/2009 1:23PM | View Shii's Profile | # | ||||||
|
Shii Posted:
Unfortunately no. Bug reports are valued, but there’s a difference between a bug and an exploit. An exploit allows you to advance in the game in a malicious way, or perhaps to make people do things with their accounts that they didn’t want to do.
Fortunato Posted:
Sure.
LRFLEW Posted:
Nah, that’s just a bug, sorry. |
||||||
Posted On: 02/04/2009 1:24PM | View Evil Trout's Profile | # | ||||||
|
Hmm. I’m not creative enough to hack a game, LOL.
But would that mean Johnny Mac should’ve gotten the peen for his use of scripts to unfairly advance in Kyoubai?
EDIT: Or only if he’d found you COULD exploit it that way and decided to report it privately Shii edited this message on 02/04/2009 1:39PM |
||||||
Posted On: 02/04/2009 1:26PM | View Shii's Profile | # | ||||||
|
So if the flezz exploit were never used before and i decided to unleash it today, i wouldn’t get the peen because I abused it?
Totally reasonable but that kills the fun of exploiting imo.
Tough call on this actually. You can’t really win everyone’s support. TUBSWEETIE edited this message on 02/04/2009 1:38PM |
||||||
Posted On: 02/04/2009 1:36PM | View TUBSWEETIE's Profile | # | ||||||
|
TUBSWEETIE Posted:
Yes that true. I used a exploint, the reported and didnt got the e-peen. But got the fun Log in to see images! |
||||||
Posted On: 02/04/2009 1:39PM | View ANGRY HOBO's Profile | # | ||||||
|
This thread should be sticky’d so these questions won’t keep coming up. |
||||||
Posted On: 02/04/2009 1:42PM | View OrsonScottCard's Profile | # | ||||||