13
ATF updates/Free to use
submitted over 4 years ago by Synysterxvo

Whats up With atf? I've been out of the mixing loop for a few years and noticed a lot of changes. Something Something about bitcoin mining, scott not running it etc.
can i get a low down? Is it safe to use?

Comments
Sort
12 points
 
by Kittybit8over 4 years agoI found my thrill on ID10-T’s hill

Scott sold ATF to Flavorah so ATF is now under new management.

The bitcoin mining were from Scott's time.

So yes, more safe than ever to use and it's also constantly being updated now, compared to when Scott was running the show.

8 points
 
by Stank_Leeover 4 years ago

I was so confused, I thought you were talking about the bureau of Alcohol Tobacco Firearms lol

1 points
 
by [deleted]over 4 years ago

I was thinking Damn! 💩 just got real up in here myself🤣

1 points
 
by [deleted]over 4 years ago

[removed]

8 points
 
by Redditors_DontShowerover 4 years ago

the bitcoin mining thing scared the shit out of me, I didn't know about it til this thread.

I had noticed that ATF was better/free now, which is a major plus, as I refused to pay for it (it sucked cock, I've ranted about it before from a software engineers perspective.

I found 3 different sql injection points and pointed out a major exploit on his server allowing root access, so contacted whoever was running it and never got a response... five emails, nothing, no way to contact him.

I'll admit that I thought about exploiting the server and ripping its code/database then posting proof of this on this sub just so the fucking owner would get scared into caring about the site/community for a minute or risk others using some basic whitehat tools and having everything stolen including peoples payment details... but I had second thoughts when I thought about the spaghetti code that's prolly the backend of ATF.

had I known about the btc mining I'd likely have shown the community the emails I sent. that's mad scummy/money hungry.

I'll check to see if everything koshar later on with the site again and send the reports to flavorah if the sql injection points are still open... one of the exploits had to do with the m-payment redirect page, so that's at least gone.

I will also check if the old m-payment scripts are accessible, a lot of webmasters forget to delete old scripts with sql injection points exploitable after the "feature" is removed

at least flavorah cares about its website and isn't all about quick money

​

side edit: I'm no hacker, I don't wear a hat, don't bother me.

before becoming an adult and getting a career as a sw engineer I maintained + developed a few mid-traffic websites (no turnkey stuff or blogs, as an example one was a myspace ripoff, thinking I'd be the next tom, but 30k members in a year is nothing but a few g's. still, for a 15 yr old it's pretty good. it had more than average amount of "hackers" attempt shit on it though) by myself, so I had to learn how to use a lot of secops tools in order to survive, because I had nearly no money

I only pissed about looking for security flaws on atf because I was bored & felt like trying out the latest (at the time) version of kali linux on a vm. didn't expect to find anything, wasn't looking to steal ur secret recipes don't worry

6 points
 
by TeslaDelMarover 4 years agoI Survived Grack

Feel free to PM me with details. I took over the site in January, haven't gotten any emails from you.

3 points
 
by Redditors_DontShowerover 4 years ago

this was before corona started, AFAIR there was some talk of an alternative to ATF/ELF being made by somebody/the community? I feel like there was a sticky asking what features they'd like to see on an "alternative" ATF type site, or something like that. I'm fuzzy on what exactly it was

I'd have to go look for my rant to see exactly when I tried to email whomever.

I think the first email was to the registered email address on the atf.com domain (from a whois search) then the rest were to support@atf.com. I sent the emails from a protonmail address, it wasn't from the atf web form.

I'll PM you tomorrow when I get home to my pc. I'll fire up burp and aa fuzzer to run the same tests I did last time to find out what was wrong and tell you exactly what needs to be fixed, if anything.

(btw you own flavorah? great f'ing job with somehow hitting a homerun with the 50 or so flavours I've drunkenly bought without an initial clue of how they've reviewed or used in published recipes. it's rare that I'd praise a company but I think you guys are amazing at what you do, so I'm excited that ATF is in good hands & I'm excited for the future)

5 points
 
by TeslaDelMarover 4 years agoI Survived Grack

Gotcha, well I didn't have email access before late Jan, so before my time anyway.

I don't own Flavorah, I'm the developer they hired to take it over.

Appreciate the follow-up, I'll definitely patch anything you can find.

6 points
 
by isuamadogover 4 years agoRenaissance Mixer

ATF and Beyond

4 points
 
by Synysterxvoover 4 years ago

Cool, thank you!

4 points
 
by Synysterxvoover 4 years ago

Oh sweet! Thank you for the information.

3 points
 
by bigtidderover 4 years agoSalty Dog

I'm super-happy with all the changes to ATF.

However there is One-Last-Thing that is still preventing me from jumping in:

Account creation / log-in with plain old email + password.

I don't use Google. I don't use Facebook. I don't use Twitter, Steam, or Twitch either.

I use email (non-google).

-7 points
 
by EdibleMalfunctionover 4 years agoI found my thrill on Blueberry Hill

Could have just searched for this here, ya know?

4 points
 
by Synysterxvoover 4 years ago

I did search. and found nothing in relation to the overall safety/new ownership etc. a few posts on it freezing, going down. last update of any importance was from q a year ago apologizing for the servers being down.

6 points
 
by T-a-r-a-xover 4 years ago

Weird. If you search on "atf" and limit to this sub, the very first hit (sorted by "relevance") is the Tuesday Tutorial : ATF and Beyond, explaining everything.

3 points
 
by Synysterxvoover 4 years ago

I searched for "All the flavors" Which i did not see that included in the search. and Honestly, on a topic titled "Tuesday Tutorial" Id have probably skipped it if i had as im not looking for Tutorials

Site copyright © 2025 DIY Compendium. Data courtesy of Reddit.