<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: NOTICE TO MODERATORS</title>
	<atom:link href="http://habitablezone.com/2012/05/21/notice-to-moderators/feed/" rel="self" type="application/rss+xml" />
	<link>https://habitablezone.com/2012/05/21/notice-to-moderators/</link>
	<description></description>
	<lastBuildDate>Fri, 03 Apr 2026 22:41:18 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: bowser</title>
		<link>https://habitablezone.com/2012/05/21/notice-to-moderators/#comment-15255</link>
		<dc:creator>bowser</dc:creator>
		<pubDate>Wed, 23 May 2012 01:32:35 +0000</pubDate>
		<guid isPermaLink="false">http://habitablezone.com/?p=15345#comment-15255</guid>
		<description>Sometimes you have to screw with it a while. :-)</description>
		<content:encoded><![CDATA[<p>Sometimes you have to screw with it a while. <img src='https://habitablezone.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>https://habitablezone.com/2012/05/21/notice-to-moderators/#comment-15252</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Wed, 23 May 2012 00:28:56 +0000</pubDate>
		<guid isPermaLink="false">http://habitablezone.com/?p=15345#comment-15252</guid>
		<description>I moved your post to Community so I wouldn&#039;t have to talk in public about the fact that you found a rather serious hole in the Zone&#039;s security. I read your clarification this morning, reproduced it and discovered a design flaw in security, and I&#039;ve spend the rest of the day fixing it.

I&#039;d welcome it if you&#039;d like to verify my claim to have fixed it. The hole consisted of fooling the site into thinking it&#039;s displaying an unrestricted page, i.e. anything other than Community, while displaying a post that should have been restricted; i.e. one from Community. 

The software formerly responded to appending the code for a board other than Community on to the URL, such as &quot;prosc_ttid=7&quot;. If you display a Community post (right-click the title and launch in a new tab or window) while logged-in, that should work fine. Log out, and the post should be inaccessible. Append &quot;?prosc_ttid=7&quot; to the URL in the address bar, and try again. The page should lift its skirts just a little bit, coyly showing posts in Recent Posts that are public and OK to see...but no Community posts there, or in the center.

So I hope, anyway.

Thanks again for your help, Johannes.</description>
		<content:encoded><![CDATA[<p>I moved your post to Community so I wouldn&#8217;t have to talk in public about the fact that you found a rather serious hole in the Zone&#8217;s security. I read your clarification this morning, reproduced it and discovered a design flaw in security, and I&#8217;ve spend the rest of the day fixing it.</p>
<p>I&#8217;d welcome it if you&#8217;d like to verify my claim to have fixed it. The hole consisted of fooling the site into thinking it&#8217;s displaying an unrestricted page, i.e. anything other than Community, while displaying a post that should have been restricted; i.e. one from Community. </p>
<p>The software formerly responded to appending the code for a board other than Community on to the URL, such as &#8220;prosc_ttid=7&#8243;. If you display a Community post (right-click the title and launch in a new tab or window) while logged-in, that should work fine. Log out, and the post should be inaccessible. Append &#8220;?prosc_ttid=7&#8243; to the URL in the address bar, and try again. The page should lift its skirts just a little bit, coyly showing posts in Recent Posts that are public and OK to see&#8230;but no Community posts there, or in the center.</p>
<p>So I hope, anyway.</p>
<p>Thanks again for your help, Johannes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: johannes</title>
		<link>https://habitablezone.com/2012/05/21/notice-to-moderators/#comment-15226</link>
		<dc:creator>johannes</dc:creator>
		<pubDate>Tue, 22 May 2012 02:49:15 +0000</pubDate>
		<guid isPermaLink="false">http://habitablezone.com/?p=15345#comment-15226</guid>
		<description>It seems to work in the described manner only if I go to the site from the side bar but not from the top bar.
In other words, if I open a site such as flame or some other board from the side bar, then go to the community board through the side bar, that is when the words “flame” or whatever board still remain on my screen, but at the same time it lets me in the community board. At least to read the post. did you design it that way?
Seems to be consistent.</description>
		<content:encoded><![CDATA[<p>It seems to work in the described manner only if I go to the site from the side bar but not from the top bar.<br />
In other words, if I open a site such as flame or some other board from the side bar, then go to the community board through the side bar, that is when the words “flame” or whatever board still remain on my screen, but at the same time it lets me in the community board. At least to read the post. did you design it that way?<br />
Seems to be consistent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>https://habitablezone.com/2012/05/21/notice-to-moderators/#comment-15214</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Mon, 21 May 2012 22:16:13 +0000</pubDate>
		<guid isPermaLink="false">http://habitablezone.com/?p=15345#comment-15214</guid>
		<description>Did as you described, but Community showed the access-denied message.

Does this happen to you consistently, Johannes? If so, can I get some more info, like whether you have cookies and JavaScript enabled. The Zone doesn&#039;t place any kind of permanent tracking cookies, but it does need a transient session cookie to consistently recognize you.</description>
		<content:encoded><![CDATA[<p>Did as you described, but Community showed the access-denied message.</p>
<p>Does this happen to you consistently, Johannes? If so, can I get some more info, like whether you have cookies and JavaScript enabled. The Zone doesn&#8217;t place any kind of permanent tracking cookies, but it does need a transient session cookie to consistently recognize you.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
