V3NTUS
Well-known member
Hi katsulynx (@Lukas W. ) I would like to point out something I think should be taken into consideration.
Altough using the HIDE bbcode doesn't display the content on the thread until you like/reply (depending on the settings you specify), there's a hole in this script. If people use the search, they can search for hidden content as well.
Example:
let's say I put a password into the hide bbcode. I'd do this way:
[hide] a1s2d3f4g5 [/hide]
Now, if a user, by search (doing Search by Thread selecting a single thread or even by using the generic forum search) goes looking for "a1s" (trying to guess the password) the search will display the thread if the result matches, then, he might keep trying adding another letter, let's say: "a1sx".
No results because it doesn't match, but this also means he can still try again and again until he guesses the final hidden text: a1s2d3f4g5 .
This shouldn't be a problem for most people (including me), but if the hidden content can only be unlocked by upgraded accounts (paid), smart people might use this exploit to find hidden content, so I was thinking about making it possible to strip the content of [hide] bbcodes from the searches, too, if possible.
I hope it helps.
Altough using the HIDE bbcode doesn't display the content on the thread until you like/reply (depending on the settings you specify), there's a hole in this script. If people use the search, they can search for hidden content as well.
Example:
let's say I put a password into the hide bbcode. I'd do this way:
[hide] a1s2d3f4g5 [/hide]
Now, if a user, by search (doing Search by Thread selecting a single thread or even by using the generic forum search) goes looking for "a1s" (trying to guess the password) the search will display the thread if the result matches, then, he might keep trying adding another letter, let's say: "a1sx".
No results because it doesn't match, but this also means he can still try again and again until he guesses the final hidden text: a1s2d3f4g5 .
This shouldn't be a problem for most people (including me), but if the hidden content can only be unlocked by upgraded accounts (paid), smart people might use this exploit to find hidden content, so I was thinking about making it possible to strip the content of [hide] bbcodes from the searches, too, if possible.
I hope it helps.