Re: [ALERT!!!] Major back door in AScii PFiles!!!

From: Nudd ap Mawr (nudd@MUD.SHADOWWIND.ORG)
Date: 01/28/98


On Tue, 27 Jan 1998, Chris Jacobson wrote:
:
:My MUD was hacked several times like this until I was finally able to
:track it down.
:
:The "solution" to this is to parse descriptions to be written to the
:file, replacing "~" with a blank space.
:

Or you could just change the order that they are saved on disk
(save_to_char) and have the description save first.  Another thing, if you
use snippits without modifing them at all, then you are opening yourself
up to hacking attempts.  So, next time modify how the tags are done so
that they are different from the snippit.

--
Dez.

void signature () {
  printf ("Praise not the day until evening has come; a woman\n"
          "until she is burnt; a sword until it is tried; a maiden until\n"
          "she is married; ice until it has been crossed; beer until it\n"
          "has been drunk.  -- Viking Proverb\n");
}


     +------------------------------------------------------------+
     | Ensure that you have read the CircleMUD Mailing List FAQ:  |
     | http://democracy.queensu.ca/~fletcher/Circle/list-faq.html |
     +------------------------------------------------------------+



This archive was generated by hypermail 2b30 : 12/15/00 PST