GBATemp Account Exploit

  • Thread starter Thread starter DavidRO99
  • Start date Start date
  • Views Views 6,208
  • Replies Replies 67
  • Likes Likes 2
Status
Not open for further replies.

DavidRO99

Average Ryzen user.
Member
Joined
Jun 11, 2016
Messages
1,018
Reaction score
301
Trophies
0
Age
28
Location
your back-door
XP
968
Country
Korea, North
I think the admins should look into this so for debugging I made a tutorial!
I hope this is possible to fix by using some type of blocker as I dont want to see somebodys account get stolen by them not knowing what they are doing with their cookies.
This is possible using cookies so... here is how to do it!
  • Step 1. Install EditThisCookie for Chrome
  • Step 2. Go to GBATemp and click on the cookie
  • Step 3. Click export and sign out of your account
  • Step 4. Click back on the cookie and then on the Trash until there is no cookie left
  • Step 5. Click on the Import icon
  • Step 6. Paste the cookie you just copied and click on the checkmark
  • Step 7. Refresh the page.
  • Step 8. Be amazed at how this works on netflix aswell
 
I think the admins should look into this so for debugging I made a tutorial!
I hope this is possible to fix by using some type of blocker as I dont want to see somebodys account get stolen by them not knowing what they are doing with their cookies.
This is possible using cookies so... here is how to do it!
  • Step 1. Install EditThisCookie for Chrome
  • Step 2. Go to GBATemp and click on the cookie
  • Step 3. Click export and sign out of your account
  • Step 4. Click back on the cookie and then on the Trash until there is no cookie left
  • Step 5. Click on the Import icon
  • Step 6. Paste the cookie you just copied and click on the checkmark
  • Step 7. Refresh the page.
  • Step 8. Be amazed at how this works on netflix aswell
But how'd you find this? Were you trying to hack GBATemp?? :creep:
 
Someone will have to get access to your cookies/computer first.
Really easy with SQL Injection/Phising

--------------------- MERGED ---------------------------

But how'd you find this? Were you trying to hack GBATemp?? :creep:
Nah, just trying to get into netflix without owning a account(and I succeded xD) so I decided to try this with GBATemp
 
  • Like
Reactions: ThePanchamBros
It is easy.... there are plenty of tutorials about doing it with just an image for example. All you need is a vulnerable site.
Phishing maybe if the user is stupid but SQLi is not easy, even if the vulnerabilities are there...
 
Why post the proccess tho, now people can use it to rob the accounts ;-;

you should had just sent it in a PM to mods...
 
It is easy.... there are plenty of tutorials about doing it with just an image for example. All you need is a vulnerable site.
I highly doubt Temp is vulnerable to SQL injection. Phising could also be used to get a password directly, there's no reason people would go out of the way to get the cookie instead.

Also, basically what @UniqueGeek said. There's no easy way around this because of how cookies work.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum