OP 14 August, 2022 - 01:45 AM
The Score and Underscore BUG.
How i found it:
Quiet for the shoutbox I decided to enter the profile of the users who spoke. And I found something strange, in the case of some users their cio URL was not "correct".
What do I want to say with that. It had characters that shouldn't be there. Those characters are numbers from 0 to 9 and "_" "-".
This is where I start to investigate a bit about the users and realize how the bug "works".
How it works:
Basically, any registered user with his name a "_" or "-" affected new users with that same name, what do I mean by that? Here is an example.
Let's say there is a user who registered in 2019, under the name "--udpcat", "-udpcat", "-udpcat-" or similar. And now a user is registered with the simple name of "udpcat". That user would have the display of the name but its URL would not correspond to its true profile. If the user puts "cracked.io/udpcat" that link would redirect to another user's account that was created with the special characters. And the url of the user with the name "udpcat" in the url would contain as many "-" as the user with special characters was registered followed by some numbers, which would be his UID. Example, the "old" user is "udpcat__" the "new" user who has the user "udpcat" his url would be "cracked.io/udpcat--UID" It is a bit complex to understand that's why I will put an image.
Image:
The issue on the forum:
Here I am going to show some of the users who suffer from this corrupted url.
1.
Affected urls:
https://cracked.io/blvck--3298885
https://cracked.io/blvck
2.
Affected urls:
https://cracked.io/berlin--2339157
https://cracked.io/berlin
In the event that information is missing or you simply want to make this bug better understood, I will edit the post with improvements.
How i found it:
Quiet for the shoutbox I decided to enter the profile of the users who spoke. And I found something strange, in the case of some users their cio URL was not "correct".
What do I want to say with that. It had characters that shouldn't be there. Those characters are numbers from 0 to 9 and "_" "-".
This is where I start to investigate a bit about the users and realize how the bug "works".
How it works:
Basically, any registered user with his name a "_" or "-" affected new users with that same name, what do I mean by that? Here is an example.
Let's say there is a user who registered in 2019, under the name "--udpcat", "-udpcat", "-udpcat-" or similar. And now a user is registered with the simple name of "udpcat". That user would have the display of the name but its URL would not correspond to its true profile. If the user puts "cracked.io/udpcat" that link would redirect to another user's account that was created with the special characters. And the url of the user with the name "udpcat" in the url would contain as many "-" as the user with special characters was registered followed by some numbers, which would be his UID. Example, the "old" user is "udpcat__" the "new" user who has the user "udpcat" his url would be "cracked.io/udpcat--UID" It is a bit complex to understand that's why I will put an image.
Image:
The issue on the forum:
Here I am going to show some of the users who suffer from this corrupted url.
1.
Affected urls:
https://cracked.io/blvck--3298885
https://cracked.io/blvck
2.
Affected urls:
https://cracked.io/berlin--2339157
https://cracked.io/berlin
In the event that information is missing or you simply want to make this bug better understood, I will edit the post with improvements.