Hi everyone,
I feel the need to come on reddit and make a public apology on behalf on drugslist. When technical questions are asked, I'm the one giving the answers to our drugslist admin.
I want to apologize to the_avid, Magnus05, and anyone else I was rude to. I was an idiot, and I shouldn't have become so defensive about my careless oversight. I should have responded in a collegial, gracious, and respectable manner to people's concerns. But, because I was embarrassed that I had such a stupid oversight, I reacted poorly and was rude. I do appreciate the goodwill nature of this community, I fucked up and I apologize.
It was potentially a serious bug and was a stupid oversight. Thankfully nothing serious happened as a result (a few unapproved user accounts were created), and the issues were correctly immediately after being pointed. Technically speaking, we weren't using prepared statements consistently (shouldn't have happened), but everything is now uniform.
We're having a second security team look over our work and perform a blackbox pen test on a mirrored, userless version of the site. In the spirit of being as transparent as possible, we will release the results.
I apologize again for my arrogant response, and we do appreciate when users report bugs. It was my fault for acting childishly and again, I would like to apologize to the_avid and Mangus05.
-dl lead developer
[deleted]