Giter Club home page Giter Club logo

idealtf's People

Stargazers

 avatar  avatar

Watchers

 avatar  avatar  avatar

idealtf's Issues

Potential login exploit by overloading login system

By entering massive amounts of corrupted and malformed data, the login dialogue can be bypassed. While this doesn't allow users to login, it could still be misused with potentially dangerous uses. This issue affects all bot versions including v2.0.1 and v1.1.0. (AHK)

TBDebug.bat serves no function?

TBDebug.bat serves no valid or useful function to the code and is not used anywhere within the main file. Should something be done about it or just removed?

Server port forwarding completely broken

I've been attempting to debug this for like 2 hours (assuming a code error caused by v2.1.0) and finally figured out the cause.

A few days ago I switched routers to a newer and 3x faster model. After the server switched over, port forwarding is broken. While Port 80 is configured open for inbound requests correctly, it doesn't work for some bizarre reason. You can try this out by visiting ITFautoupdate.txt and attempting to access the Server Public IP address in your browser. If it doesn't work, the server is down by either the server or router's fault.

This is hopefully a simple fix or there might be a major problem. Either the router is completely broken for port forwarding, a router or server firewall is incorrectly configured or I screwed up somewhere during configuration (hopefully the latter).

Security breach with logins

Discovered a security breach where entering a specific string into the login InputBoxes can bypass logins and even access administrative features.

Support for Firefox and IE/Edge

Support for Firefox and possibly IE/Edge might come in the future but there is major compatibility issues caused by versioning. Firefox will be easy to implement (the bot originally ran on Firefox) but IE may be too unstable and will need a crash/error detection. Edge is incompatible with a few current trade systems.

Maximise button on the control panel is dead

This feature was never wired in as there is no need to maximise the program (content would be stretched too much making it quite ugly). Maybe if more features (like the upcoming graphs of recent trades and chatbot, hint hint) get added this might be required.

Finish off TradeBot.bat

TradeBot.bat needs to be finished off to a stable, usable state. The bot must be able to check at least the first 8 item slots for an item in less than 5 seconds and Enable mobile auth compatibility. This will require the code tho be transferred over from previous commits, like this one.

TradeBotBackground.exe exploit when exiting launcher during update

If you open and wait for 1 min on the exit dialogue while there is a launcher update underway, it will cause a fatal error to TradeBotBackground.exe.

The cause is that when the exit dialogue is open, it halts the update subprocess leaving aupd.bat being stuck as 'used by another process' making it unreadable by TradeBotBackground.exe.

The exit dialogue can be used to exploit this way by halting the bot after update download has finished and modifying the auto update files.

Saving settings and restarting adds '...' to the end of the entry

When saving your settings your entry may have a '...' added after it causing multiple problems. The cause of this is unknown but can be fixed by going to \config\settings\ and removing the ... from all the file's contents. The cause of this is completely unknown.

Removal of login system and open access to all

The entire login system and user account system has been scrapped. As of v2.1.5 logins will no longer work and an upgrade will be required. All users will get all features unlocked.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.