GBATemp Account Exploit

Status
Not open for further replies.

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,041
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,006
Country
Portugal
Lol you think its "easy"
It's not really that hard, phishing. I once made a phishing site just to test it out. It was using Minecraft's website. I literally just downloaded the site and uploaded it to a server, then changed the login function to just print the data to a file. lol. It was easy. I took it down shortly after, but apparently someone found it and tried to login. lmao.
 

Joe88

[λ]
Global Moderator
Joined
Jan 6, 2008
Messages
12,736
Trophies
2
Age
36
XP
7,438
Country
United States
this isnt new, even sites like amazon are vulnerable
theres even an android app that will session hijack (you just have to be on the same internet connection as them)
 
Last edited by Joe88,
  • Like
Reactions: astronautlevel

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,041
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,006
Country
Portugal
I highly doubt Temp is vulnerable to SQL injection. Phising could also be used to get a password directly, there's no reason people would go out of the way to get the cookie instead.

Also, basically what @UniqueGeek said. There's no easy way around this because of how cookies work.
this.
 

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,041
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,006
Country
Portugal
Still, it is more secure than just letting people play with your account
Hell, I only use 2FA for Steam (cuz trades and market and all) and for the bank-related stuff. GBATemp is important, but I'm not important enough that anyone will bother hijacking my account just to piss me off soooo ya
 
  • Like
Reactions: Deleted User

Luckkill4u

4 guys in a car ( ͡° ͜ʖ ͡°)
Member
Joined
Jul 13, 2008
Messages
1,028
Trophies
1
Age
30
Location
Insomnia
Website
www.gbatemp.net
XP
1,131
Country
Canada
It's not really that hard, phishing. I once made a phishing site just to test it out. It was using Minecraft's website. I literally just downloaded the site and uploaded it to a server, then changed the login function to just print the data to a file. lol. It was easy. I took it down shortly after, but apparently someone found it and tried to login. lmao.
I was talking more about SQLi, Phishing is easy but also easy to spot.
 

migles

All my gbatemp friends are now mods, except for me
Member
Joined
Sep 19, 2013
Messages
8,033
Trophies
0
Location
Earth-chan
XP
5,299
Country
China
can't this be used on almost every fucking site that auto logins?
i mean, how else the auto login system works?, a cookie is deposited on your computer, the website reads it and aknoledges that it's you
cookies guarantees that autologin works even if you change your ip or country..

if you have the cookie, that means it's you...
there is only 2 ways i can think to prevent this, get rid of autologin or when user logs out (by using the logout) that cookie is discarted and you need to login again
 

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,041
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,006
Country
Portugal
What would people want to do with someone's GBAtemp account anyway? I mean there's really nothing they would be able to get out of it.
gotta get them users banned by posting on their behalf :D
 
D

Deleted User

Guest
If you get someone's cookies you can actually log into their account
And how would you get somebody';s cookies? If it is as simple as running a script or a chrome extention, sure that might be a problem. But it isn't a prblem when you have to be on the network or have to know the email. It's kinda a non-problem at that point.
 

Chary

Never sleeps
Chief Editor
Joined
Oct 2, 2012
Messages
12,352
Trophies
4
Age
27
Website
opencritic.com
XP
128,884
Country
United States
Two Factor Authentication? That could be implemented, I assume, but that can be annoying.
As much as I love GBAtemp, I'd rather be hacked than give out my phone number. After hearing the rash of account bans on PSN, I added 2FA to my PS4, and suddenly I'm getting all sorts of weird spam calls. I only call three people on my phone, so it's weird that out of the blue, my number seems to be so find-able. I don't trust that sort of thing.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Veho @ Veho: Looks like Link's Awakening was metaphorical.