<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Patrick Sapinski</title>
	<atom:link href="http://sapinski.com/feed" rel="self" type="application/rss+xml" />
	<link>http://sapinski.com</link>
	<description></description>
	<lastBuildDate>Sun, 17 Apr 2011 07:34:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.1</generator>
		<item>
		<title>Philip Linden: Wow that is a really big problem.</title>
		<link>http://sapinski.com/http:/sapinski.com/main</link>
		<comments>http://sapinski.com/http:/sapinski.com/main#comments</comments>
		<pubDate>Thu, 23 Aug 2007 01:34:58 +0000</pubDate>
		<dc:creator>k\o\w</dc:creator>
				<category><![CDATA[Second Life]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sapinski.com/blog/?p=20</guid>
		<description><![CDATA[I was going through some files today and found this chatlog. It&#8217;s from when I reported an exploit where an avatar could debit money from any other avatar in SL. I reported it to the emergency e-mail they gave the libsl folk, and Brent Linden was awake within an hour taking care of it. 10 [...]]]></description>
			<content:encoded><![CDATA[<p>I was going through some files today and found this chatlog. It&#8217;s from when I reported an exploit where an avatar could debit money from any other avatar in SL. I reported it to the emergency e-mail they gave the libsl folk, and Brent Linden was awake within an hour taking care of it. 10 minutes after getting into the office, Philip messaged me:</p>
<p>[7:10]  Philip Linden: hey there!<br />
[7:10]  Gene Replacement: hi what&#8217;s up<br />
[7:10]  Philip Linden: can I come and talk to you about your reported exploit?<br />
[7:11]  Gene Replacement: ok sure but I&#8217;m not at a nice place<br />
[7:11]  Philip Linden: let&#8217;s go somewhere else then.<br />
[7:11]  Philip Linden: hang on.<br />
[7:12]  Philip Linden: actually let&#8217;s talk in IM to be really secure.<br />
[7:12]  Gene Replacement: secure :p<br />
[7:12]  Philip Linden: OK so can you tell me the time and source-&gt;dest of the test you did?<br />
[7:13]  Gene Replacement: honestly, I have no idea. I&#8217;ve been messing with packet shaping SL stuff for a few hours last night/today and was messing with various stuff.<br />
[7:13]  Gene Replacement: I debited two different avatars and paid them back to do the test.<br />
[7:13]  Philip Linden: OK which ones?<br />
[7:14]  Philip Linden: I want to look at our logs and see what is there?<br />
[7:14]  Gene Replacement: Tiny Marbles and Huns Valen<br />
[7:14]  Gene Replacement: I received their permission via voice chat<br />
[7:14]  Gene Replacement: I also debited NULL_KEY when testing it, as the idea originally came from modifying asset upload fees and the default avatar paid is NULL_KEY<br />
[7:15]  Philip Linden: OK are you referring to a transact between you and him at 3AM this morning?<br />
[7:16]  Philip Linden: that is what I see.<br />
[7:16]  Gene Replacement: yeah that sounds right<br />
[7:16]  Gene Replacement: I was messing with the upload fees a few days ago but wanted to try spoofing the payment source/destination today<br />
[7:16]  Philip Linden: there is a &#8216;gift&#8217; transact of value 1L$?<br />
[7:16]  Philip Linden: is that correct?<br />
[7:16]  Gene Replacement: to Huns?<br />
[7:17]  Philip Linden: there is first a payment from huns-&gt;gene, and then backwards.<br />
[7:17]  Gene Replacement: yes that is correct<br />
[7:17]  Philip Linden: OK so what account were you logged in as when you sent the packets?<br />
[7:18]  Gene Replacement: Gene Replacement<br />
[7:18]  Philip Linden: So basically you were able to get Huns to xfer to you, though you were logged in as you?<br />
[7:18]  Gene Replacement: yes<br />
[7:18]  Gene Replacement: it&#8217;s really simple I could do it to you :p<br />
[7:19]  Philip Linden: OK<br />
[7:19]  Gene Replacement: you are asking me to debit money from you?<br />
[7:20]  Philip Linden: can you do it right now?<br />
[7:20]  Gene Replacement: yes<br />
[7:20]  Philip Linden: OK let&#8217;s do that so we have a good record.<br />
<span style="font-weight: bold">[7:20]  Philip Linden: XFER L$1 from me to you.</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:20]  Gene Replacement: ok it will take a few mins</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:21]  Philip Linden: OK</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:22]  Gene Replacement: there we go</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:22]  Philip Linden: Got it.</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:22]  Philip Linden: Let me check the logs.</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:22]  Gene Replacement: no I got it :p</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:23]  Philip Linden: OK I&#8217;ve got it confirmed in the logs.</span><br style="font-weight: bold" /><span style="font-weight: bold">[7:23]  Philip Linden: Wow that is a really big problem.</span><br />
[7:23]  Philip Linden: I can&#8217;t tell you how much I appreciate the find.<br />
[7:24]  Philip Linden: Why we aren&#8217;t confirming that event at the server is beyond me,<br />
[7:24]  Philip Linden: OK so it looks like we&#8217;ve at least got good logs,<br />
[7:24]  Philip Linden: which would allow us to look for this happening.<br />
[7:24]  Philip Linden: I was still able to see that you were the one who initiated the transfer (from me to you)<br />
[7:25]  Philip Linden: so that makes me feel somewhat better in terms of the time it will take to fix.<br />
[7:25]  Gene Replacement: this is why an open policy on reverse engineering is a good thing <img src='http://sapinski.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[7:25]  Philip Linden: Obviously please keep under wraps.  We&#8217;ll probably fix it today.<br />
[7:25]  Gene Replacement: yup, I don&#8217;t plan on telling anyone how to do this.<br />
[7:26]  Philip Linden: OK thanks.<br />
[7:26]  Philip Linden: We will be working on it within couple hours.<br />
[7:26]  Philip Linden: I<br />
[7:26]  Philip Linden: I&#8217;m in the office now.<br />
[7:27]  Philip Linden: OK talk to you soon.<br />
[7:27]  Gene Replacement: ok bye<br />
[7:27]  Second Life: User not online &#8211; message will be stored and delivered later.</p>
<p>The chatlog is from August 1st 2006, about a month and a half before my Gene Replacement account was banned in the Voted 5 lolocaust. It had been an exciting few months, with megaprims and all kinds of other sneaky exploits. One of my favorite memories from then was driving around Lindens like little Tonka trucks in Ambleside then apologizing in another language for me and my silly foreign ways.</p>
]]></content:encoded>
			<wfw:commentRss>http://sapinski.com/http:/sapinski.com/main/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>John Edward ‘08</title>
		<link>http://sapinski.com/http:/sapinski.com/main</link>
		<comments>http://sapinski.com/http:/sapinski.com/main#comments</comments>
		<pubDate>Tue, 27 Feb 2007 04:00:25 +0000</pubDate>
		<dc:creator>k\o\w</dc:creator>
				<category><![CDATA[Second Life]]></category>

		<guid isPermaLink="false">http://sapinski.com/blog/?p=15</guid>
		<description><![CDATA[John Edwards&#8217; campaign came to SL: Anonymous bought land next to John Edwards&#8217; campaign. Anonymous then asked goons to build on his land: John Edwards vs. John Edward 2008 Presidential Elections Seriously. He can read minds. I&#8217;ve made my decision.]]></description>
			<content:encoded><![CDATA[<p>John Edwards&#8217; campaign came to SL:</p>
<p><a class="imagelink" title="edwards_001.jpg" href="http://www.sapinski.com/wp-content/uploads/2007/02/edwards_001.jpg"><img id="image4" src="http://www.sapinski.com/wp-content/uploads/2007/02/edwards_001.thumbnail.jpg" alt="edwards_001.jpg" /></a><br />
Anonymous bought land next to John Edwards&#8217; campaign.<br />
Anonymous then asked goons to build on his land:</p>
<p><a class="imagelink" title="edwards_002.jpg" href="http://www.sapinski.com/wp-content/uploads/2007/02/edwards_002.jpg"><img id="image5" src="http://www.sapinski.com/wp-content/uploads/2007/02/edwards_002.thumbnail.jpg" alt="edwards_002.jpg" /></a><br />
John Edwards vs. John Edward<br />
2008 Presidential Elections</p>
<p><a class="imagelink" title="edwards_003.jpg" href="http://www.sapinski.com/wp-content/uploads/2007/02/edwards_003.jpg"><img id="image6" src="http://www.sapinski.com/wp-content/uploads/2007/02/edwards_003.thumbnail.jpg" alt="edwards_003.jpg" /></a><br />
Seriously. He can read minds. I&#8217;ve made my decision.</p>
]]></content:encoded>
			<wfw:commentRss>http://sapinski.com/http:/sapinski.com/main/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

