Ugh. News update today, confirmed I was correct in my predictions. Once FTO gets back online, it will only be a matter of time before someone less than friendly has their way with the game's glitches. I no longer have interest in aiding FTO.
As for the rest of the story (be warned, I'm going to be blunt, and I'll probably look like an asshole)
Lumin is overconfident in his skills.* When I pointed out simple problems, he fixed them, not too important tho.
Then I pointed out larger problems, but I said it rather... umm... generically? He's like, "yeah, cool, good thing you found the before someone else did. How can I fix this?"
And
then I go into detail about the problems (there were four major ones), which are/were quite dangerous, including everything from trusting javascript on the client-side to XSS problems so bad it could catch unwary users and delete their accounts, or overwrite their passwords.
He believes that I had hacked the site in order to find all this info. My sources? Right-click -> View Source. "window.location="index.php";" isn't going to be keeping anyone from viewing the page.
And then the public include directory... isn't too hard to find, when errors give direct links to them. All of the php files, including the chron.php which runs hourly(? I think). Entirely unsecure. He totally saw this in the wrong way, I'm a terrible hacker, because, you see, his site is
very secure, so for me to actually come up with so many
huge problems I MUST have
tampered with game data, and so not only was I banned, but other users are now recommended to change their account passwords once the game resume play.
</end of rant>
In other news, I'm rather pissed off myself. My character was 5th in line to be born, but no doubt my account has been deleted by this point, and I've also been gyped out of fun for a few months. See, I like to find fledgling/insecure sites, fix them up, and take it as a challenge. Any attempt on the site I'm "protecting" is a direct assault on my own security. Maybe most people don't, but I find this a source of fun/amusement. Combined with the fact the site was bound to be hacked by someone less nice than I, we kill two birds with one stone, the site becomes secure, and I get my kicks making sure it stays that way.
Peace out,
- Natso
edit: There was a request for some proof of authenticity. As my account was banned, and Lumin refused to let me contact him any way except PM, I cannot provide screenshots. However, I can supply screenshots of the PM alerts of messages I received from him.
http://natso.darknovagames.com/files/sc1.pnghttp://natso.darknovagames.com/files/sc2.png