Thread Tools Display Modes
08-01-09, 04:29 PM   #1
speak
A Wyrmkin Dreamwalker
 
speak's Avatar
Join Date: Oct 2005
Posts: 57
v bulletinauthorization.blackapplehost.com ?

when i open some of the threads in the UI section of this forum, i receive a popup saying:

A username and password are being requested by http://vbulletinauthorization.blackapplehost.com. The site says: "You must login to continue viewing this page.-3237"
This popup has a text entry box for username and for password.

for instance,i get this popup when i visit the thread here
http://www.wowinterface.com/forums/s...ad.php?t=25892

i have not entered any information in the box, but i can still post just fine.

i'm using firefox 3.5.1 with addons noscript, adblockplus and a few other minor ones.

blackapplehost.com looks like it's a free webhosting site, and looks like someone might be using it to try and scam some passwords.

Last edited by speak : 08-01-09 at 04:31 PM. Reason: additional information
  Reply With Quote
08-01-09, 04:35 PM   #2
Miralen
A Rage Talon Dragon Guard
 
Miralen's Avatar
Join Date: Dec 2006
Posts: 341
Weird popup

As a side note, I came to read this post and was hit with a window that popped up that gave me this junk:

A username and password are being requested by http://vbulletinauthorization.blackapplehost.com. The site says: "You must login to continue viewing this page.-3237"

I of course hit cancel and I could still view this thread but anyone else seen this before. I am not sure if its something on my computer or just something from the site here I have never seen if before and it only did it to me here I tried multiple other newer threads and didnt get hit with it. but each time I visit this particular thread I get hit with that message. It comes with a box for my login name and password I assume for this site but I hit cancel each time and am able to view the thread anyways.
__________________
Never hold discussions with the monkey when the organ grinder is in the room.

- Winston Churchill
  Reply With Quote
08-01-09, 04:37 PM   #3
speak
A Wyrmkin Dreamwalker
 
speak's Avatar
Join Date: Oct 2005
Posts: 57
yep heres part of the page source for WowAddonUser's signature:

Code:
<img src="http://flashenabled.files.wordpress.com/2008/05/create-a-cool-signature.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /><br />
<img src="http://vbulletinauthorization.blackapplehost.com/index.php" border="0" alt="" onload="NcodeImageResizer.createOn(this);" />
bad poster! bad!
  Reply With Quote
08-01-09, 07:16 PM   #4
Cairenn
Credendo Vides
 
Cairenn's Avatar
Premium Member
WoWInterface Admin
Join Date: Mar 2004
Posts: 7,134
Thanks for the heads up guys, we've taken care of the account. Sorry about that.
__________________
“Do what you feel in your heart to be right — for you’ll be criticized anyway.” ~ Eleanor Roosevelt
~~~~~~~~~~~~~~~~~~~
Co-Founder & Admin: MMOUI
FaceBook Profile, Page, Group
Avatar Image by RaffaeleMarinetti

Last edited by Cairenn : 08-01-09 at 07:29 PM.
  Reply With Quote
08-01-09, 09:55 PM   #5
speak
A Wyrmkin Dreamwalker
 
speak's Avatar
Join Date: Oct 2005
Posts: 57
Post

Thanks. and sorry lol, i didnt think the code i posted in this thread would be parsed :O

thanks for editing it out C
  Reply With Quote
08-09-09, 06:48 AM   #6
AnrDaemon
A Chromatic Dragonspawn
AddOn Author - Click to view addons
Join Date: Jul 2008
Posts: 156
Originally Posted by Cairenn View Post
Thanks for the heads up guys, we've taken care of the account. Sorry about that.
Well but why script handlers allowed in the forum HTML anyway? Or more precise, if there's any real need for HTML being allowed for regular users?
  Reply With Quote
08-09-09, 07:13 AM   #7
Dolby
PPAP
 
Dolby's Avatar
WoWInterface Admin
Join Date: Feb 2004
Posts: 2,341
We don't allow html. If you look at the posting rules in each forum "HTML code is Off".

The user had an image in his signature using the [img ] bbcode tag that was put behind a .htaccess/.htpasswd on their server. It happens from time to time. We either have to disallow remote img bbcode or just deal with it when it happens. I don't think many users would be happy with us removing the img bbcode. This is really a security flaw on all browsers end. The browser should see that the image is from a different domain and ignore it if its requesting authentication. Instead it tries to authenticate with the server hosting the image thus asking for a password.

There was no html in his signature. Ofcourse when you look at the source code in your browser it will show html because a browser doesnt know bbcode. The forum software parses the bbcode into "safe" html.

Last edited by Dolby : 08-09-09 at 07:25 AM.
  Reply With Quote
08-09-09, 07:51 AM   #8
AnrDaemon
A Chromatic Dragonspawn
AddOn Author - Click to view addons
Join Date: Jul 2008
Posts: 156
Oh, sorry, i misunderstood. Interesting trick.
  Reply With Quote

WoWInterface » Site Forums » Site help, bugs, suggestions/questions » v bulletinauthorization.blackapplehost.com ?


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off