<?xml version="1.0" ?><rss version="2.0">
    <channel>
	<title>ETF2L &#8211; Latest activity in &#8220;ETF2L permissions exploit&#8221;</title>
	<link>https://staging.etf2l.org/forum/league/topic-15637/</link>
	<description><![CDATA[The latest posts to this topic.]]></description>
    	<item>
    	    <title>Reply by DeNeusbeer</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277712</link>
    	    <description><![CDATA[Sorry to spoil your fun, but if I am not mistaken you were previously marked Deputy of that team. A deputy has the rights to edit a team's roster, and that includes setting these rights. Why you would be manipulating post data to do something you can do perfectly fine without, I don't know. 

(Yes, on the roster page it's hidden to edit your own role, but that's just to prevent the idiots deleting their own leader rights, it's by no means prohibited.)

If this is a matter of you thinking deputy's shouldn't be able to alter these things, take it up with the league (head) admins. They can disable it by unticking a single button.

No exploit: expected behaviour.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277712</guid>
    	    <pubDate>Mon, 14 Feb 2011 22:47:37 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by RaCio</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277532</link>
    	    <description><![CDATA[Thanks for the headsup]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277532</guid>
    	    <pubDate>Mon, 14 Feb 2011 13:23:08 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Dr. Chris</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277528</link>
    	    <description><![CDATA[<i>Quoted from .____________.</i>
		<blockquote>Stop hacking stuff chris. You're addicted, you need help.</blockquote>

HAPPY VALENTINES TO YOU TOO]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277528</guid>
    	    <pubDate>Mon, 14 Feb 2011 13:21:00 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by Manuel Magnetic Star</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277527</link>
    	    <description><![CDATA[haha :D]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277527</guid>
    	    <pubDate>Mon, 14 Feb 2011 13:20:11 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by illii</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277526</link>
    	    <description><![CDATA[Stop hacking stuff chris. You're addicted, you need help.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277526</guid>
    	    <pubDate>Mon, 14 Feb 2011 13:20:05 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Reply by D2M</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277524</link>
    	    <description><![CDATA[d2m likes this post.]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277524</guid>
    	    <pubDate>Mon, 14 Feb 2011 13:05:17 +0100</pubDate>
    	</item>
    	<item>
    	    <title>Created by Dr. Chris</title>
    	    <link>https://staging.etf2l.org/forum/league/topic-15637/page-1/?recent=277712#post=277523</link>
    	    <description><![CDATA[Your site is vulnerable to having permissions overridden by malicious postdata. :)

http://etf2l.org/teams/11861/

No leader rights to leader rights just by sending malicious postdata. Anyone can do it. This is a little bit of a bug ;)]]></description>
    	    <guid isPermaLink="false">generator=rsdiscuss&#038;baseurl=https://staging.etf2l.org&#038;feed=forum&#038;forum=league&#038;topic=15637&#038;post=277523</guid>
    	    <pubDate>Mon, 14 Feb 2011 13:03:46 +0100</pubDate>
    	</item>
    </channel>
</rss>