So I just discovered this by accident because I wanted to delete a comment I had made on someone's profile.
I used the postman addon for chrome.
You take the base url for deleting comments on profiles:
gaiaonline.com/p/xxxxxx/?mode=deletecomment&cid=xxx
insert the commentid and the user id in the x's. (you can find the cid if you hover over the "report post" link, and it will have the userid_cid (ex. gaiaonline.com/gaia/report.php?r=30&rpost=999999_99)
Then, go into postman and put the url together in there. Then click the dropdown box to the right, and select "post".
Form should appear below with "key" and "value"
Under key, put "submit". Under value, put "Yes".
Comment will be deleted. You can use this to delete a comment made by anyone on anyone's profile. You could go to an admin's page if you wanted to and delete all the comments off of their profile.
Not sure how useful this would be to others, but it was entertaining, so I figured I would share.
Results 1 to 21 of 21
- 12 Dec. 2014 01:36am #1
Delete profile comments on anyone's profile made by anyone
- 12 Dec. 2014 02:06am #2
- Join Date
- Apr. 2013
- Location
- Minnesota
- Posts
- 1,325
- Reputation
- 114
- LCash
- 0.00
+rep nice post
https://discord.gg/TvN6xUb ~ chat on discord pls.
- 12 Dec. 2014 07:03am #3
This sounds very insecure, and even the most basic of security should block it, so I'm curious if it works.
- 12 Dec. 2014 04:16pm #4
- 12 Dec. 2014 09:16pm #5
Interesting discovery. I don't play gaia anymore but even if (or when rather) this gets patched, the method behind doing this is still pretty useful info.
+repI'm lightning on my feet
- 15 Dec. 2014 08:26pm #6yup this is really me gamersoul AVA
- 15 Dec. 2014 11:08pm #7
- 17 Dec. 2014 12:48pm #8
- 17 Dec. 2014 09:47pm #9yup this is really me gamersoul AVA
- 24 Dec. 2014 06:21pm #10
- 27 Dec. 2014 06:28pm #11
Omlett beat me to it, but I was thinking the same thing. That could possibly be imitated for forums, though it might not work since (as far as I know), posts aren't given a userid.
It could be even possible to force purchases of items without losing any gold on your side, but having the gold delivered to the seller. Maybe. I'm just spitballing.
- 28 Dec. 2014 01:10am #12
Hate to shoot you guys down but a few years ago someone found a similar exploit with the Art Arenas in Gaia.
So it could possibly still work with that, but forcing trades/market/forum actions more than likely won't work.There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 29 Dec. 2014 05:20am #13
Was this never patched? Cos fairly sure it was abused all to hell ages ago by several people from another forum I used to be a part of.
- 29 Dec. 2014 08:19am #14
Doesn't work with forums, throws a permissions error page out.
Haven't tried it with anything else yet.
- 09 Feb. 2015 06:38am #15
Has anyone figured out if this extends to any other areas rather than comments?
I did try trades and marketplace purchases, but nothing happens.
- 10 Feb. 2015 01:42am #16
- 12 Feb. 2015 03:22am #17
- 21 Feb. 2015 08:23pm #18
- 21 Feb. 2015 09:52pm #19I'm lightning on my feet
- 12 Mar. 2015 06:44pm #20
Lol I think this has been patched
- 11 Feb. 2018 11:36am #21
ow