cRPG

cRPG => General Discussion => Topic started by: naruto12900 on September 26, 2012, 03:54:12 am

Title: XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 03:54:12 am

Im reporting this issue
My Proof,

visitors can't see pics , please register or login
Title: Re: Presistant XSS Vulnerabilities
Post by: Tanken on September 26, 2012, 03:54:59 am
Cool.


Story.


Your*
Title: Re: Presistant XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 04:03:43 am
bump
Title: Re: Presistant XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 04:10:34 am
Cool.


Story.


Your*

...................................................
Title: Re: Presistant XSS Vulnerabilities
Post by: isatis on September 26, 2012, 04:14:54 am
So you could like hack account?

humm...

If you wanna have a reaction, hack it first then warn... people don't usually understand a threat until the threat is accomplished...
Title: Re: Presistant XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 04:17:14 am
So you could like hack account?

humm...

If you wanna have a reaction, hack it first then warn... people don't usually understand a threat until the threat is accomplished...

Herp a derp Q_Q
Title: Re: Presistant XSS Vulnerabilities
Post by: isatis on September 26, 2012, 04:22:28 am
well, my hacker friends do that : like hack a place, then go see the owner of place and tell them the secrutity is broken and given back the stuff they hacked (usually some useless stuff like dog picture...)

I'm not telling you to steal people stuff... just like for exemple get into the account of somebody, take a pic with you doing insane thing like buying 10 hat and send it to dev with explication.....

(ps remove the link... don't give people idea xD)
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 04:57:53 am
kk i did
Title: Re: XSS Vulnerabilities
Post by: chadz on September 26, 2012, 06:50:48 am
Can you send me details via PM - I can't see anything in that screenshot.

Thanks.
Title: Re: XSS Vulnerabilities
Post by: Sarpton on September 26, 2012, 11:44:57 am
Also can you put a link to your background?  Looks badass!
Title: Re: XSS Vulnerabilities
Post by: Polobow on September 26, 2012, 12:11:04 pm
Also can you put a link to your background?  Looks badass!

First thing i thought of was Assassin's creed, but that probally isn't right...
Title: Re: XSS Vulnerabilities
Post by: Vibe on September 26, 2012, 12:51:45 pm
your background Looks badass!
Title: Re: XSS Vulnerabilities
Post by: Nessaj on September 26, 2012, 01:39:02 pm
Nice disassembler on the desktop.
Title: Re: XSS Vulnerabilities
Post by: Radament on September 26, 2012, 01:39:29 pm
which addon for firefox are you using naruto? good find anyways , i'm learning some XSS and Sql too , you used some program or did you find this by yourself?
Title: Re: XSS Vulnerabilities
Post by: Nessaj on September 26, 2012, 01:42:58 pm
i'm learning some XSS and Sql too

Then your "I steal cookies!" text have a whole new meaning :P
Title: Re: XSS Vulnerabilities
Post by: Radament on September 26, 2012, 01:44:31 pm
Then your "I steal cookies!" text have a whole new meaning :P

lol yep i steal cookies from ages but don't tell anyone i'm undercoverz :P
Title: Re: XSS Vulnerabilities
Post by: Kafein on September 26, 2012, 01:47:56 pm
Don't forget to read my biography !
Title: Re: XSS Vulnerabilities
Post by: Radament on September 26, 2012, 02:04:06 pm
cause i'm lazy i used an online tool , don't know if this could be useful

http://www.domxssscanner.com/scan?url=http%3A%2F%2Fc-rpg.net%2F (http://www.domxssscanner.com/scan?url=http%3A%2F%2Fc-rpg.net%2F)
Title: Re: XSS Vulnerabilities
Post by: Kafein on September 26, 2012, 02:16:44 pm
http://www.domxssscanner.com/scan?url=http%3A%2F%2Fc-rpg.net%2Findex.php%3Fpage%3Dselectchar%26returnpage%3Dchartitle (http://www.domxssscanner.com/scan?url=http%3A%2F%2Fc-rpg.net%2Findex.php%3Fpage%3Dselectchar%26returnpage%3Dchartitle)

visitors can't see pics , please register or login
Title: Re: XSS Vulnerabilities
Post by: Radament on September 26, 2012, 02:24:26 pm
visitors can't see pics , please register or login

visitors can't see pics , please register or login
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 02:27:42 pm
Can you send me details via PM - I can't see anything in that screenshot.

Thanks.

Sent :D
Title: Re: XSS Vulnerabilities
Post by: Lactating Vegetables on September 26, 2012, 05:20:13 pm
Thats a nice DDOS.txt on that desktop  :shock:
Title: Re: XSS Vulnerabilities
Post by: Kafein on September 26, 2012, 06:12:01 pm
visitors can't see pics , please register or login


Go daddy hidden ad.
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 06:20:41 pm
which addon for firefox are you using naruto? good find anyways , i'm learning some XSS and Sql too , you used some program or did you find this by yourself?

It's called hack bar
Title: Re: XSS Vulnerabilities
Post by: Vodner on September 26, 2012, 07:45:02 pm
I messaged chadz regarding a strat XSS vulnerability around a year ago. I'm not sure if anything ever came of it.
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 09:32:43 pm
I messaged chadz regarding a strat XSS vulnerability around a year ago. I'm not sure if anything ever came of it.



I'm checking start I don't think Thier are any anymore ill check in a little
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 26, 2012, 09:51:13 pm
visitors can't see pics , please register or login



YES IT IS!!!!!!!!!!!!!!!!
Title: Re: XSS Vulnerabilities
Post by: Elio on September 26, 2012, 09:53:55 pm
Check lottery too, I'm surprised to see when you post a trade offer, client send amount of trace cut. (5%)
Title: Re: XSS Vulnerabilities
Post by: Bjord on September 26, 2012, 10:01:03 pm
Not to be a complete dick (90%, remember), but as long as your name is "naruto12900", no one on the internet, least of all here, will take you seriously.

And that signature effectively removes all doubt about whether your name is truly inspired by that godawful anime.

Anyway, still, thanks for finding the loophole.
Title: Re: XSS Vulnerabilities
Post by: Jarlek on September 26, 2012, 10:29:27 pm
cause i'm lazy i used an online tool , don't know if this could be useful

http://www.domxssscanner.com/scan?url=http%3A%2F%2Fc-rpg.net%2F (http://www.domxssscanner.com/scan?url=http%3A%2F%2Fc-rpg.net%2F)
Why do I have this urge to press this link. OH GOD MY HAND IS MOVING BY ITSELF! D:
Title: Re: XSS Vulnerabilities
Post by: Kafein on September 26, 2012, 11:15:39 pm
Not to be a complete dick (90%, remember), but as long as your name is "naruto12900", no one on the internet, least of all here, will take you seriously.

And that signature effectively removes all doubt about whether your name is truly inspired by that godawful anime.

Anyway, still, thanks for finding the loophole.

Operational research has found out that 99,5% of people behind nicknames including "naruto" are less than 15.

Ho yeah and the same applies to names with a number at the end, or when there are mixed upper and lower case letters.

Whatever.
Title: Re: XSS Vulnerabilities
Post by: Leshma on September 26, 2012, 11:35:04 pm
Most great hackers started while they were still kids. If he was adult hacker he certainly wouldn't waste his time here.
Title: Re: XSS Vulnerabilities
Post by: Kafein on September 27, 2012, 12:43:36 am
Most great hackers started while they were still kids. If he was adult hacker he certainly wouldn't waste his time here.

Most of the people having the skills to do this are not hackers but security experts. It's about the same thing anyway. Thing is, I believe most of these guys learned their job at college. Okay you need self education to keep in touch, but there's no reason so many of them should be passionate teenagers.

Besides, a lot of cRPG players are in their thirties. And I bet it's a lot more than in many other action multiplayer games.
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 27, 2012, 01:29:33 am
Operational research has found out that 99,5% of people behind nicknames including "naruto" are less than 15.

Ho yeah and the same applies to names with a number at the end, or when there are mixed upper and lower case letters.

Whatever.


17 Years old Get at me :D
Title: Re: XSS Vulnerabilities
Post by: Radament on September 27, 2012, 02:46:38 am

Its not as good as my 2,000$ scanner XD

are you using acunetix?
Title: Re: XSS Vulnerabilities
Post by: cmp on September 27, 2012, 03:33:30 am
I cringe every time a skiddie gets called hacker.
Title: Re: XSS Vulnerabilities
Post by: Son Of Odin on September 27, 2012, 04:09:00 am
I cringe every time a skiddie gets called hacker.
A script kiddie?
Title: Re: XSS Vulnerabilities
Post by: Radament on September 27, 2012, 04:10:39 am
i know most of the so called "hackers" are using softwares to detect exploits and such , i used those sometimes but just cause i'm a lazy guy but when i started to manually sqli some stuff  that felt different , i learned something by myself , no tutorials or such , just lurking here and there but i think most of the haxorz wannabe just want to have life easy , just like reach lvl 31 in crpg with a cav char :P
Title: Re: XSS Vulnerabilities
Post by: naruto12900 on September 27, 2012, 04:59:16 am
i know most of the so called "hackers" are using softwares to detect exploits and such , i used those sometimes but just cause i'm a lazy guy but when i started to manually sqli some stuff  that felt different , i learned something by myself , no tutorials or such , just lurking here and there but i think most of the haxorz wannabe just want to have life easy , just like reach lvl 31 in crpg with a cav char :P

Im not + Most of them dont even work :\

Most or some are google dorks like Site:c-rpg.net inurl:id ext:php