GBATemp Account Exploit

Status
Not open for further replies.

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,044
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,020
Country
Portugal
Lol you think its "easy"
It's not really that hard, phishing. I once made a phishing site just to test it out. It was using Minecraft's website. I literally just downloaded the site and uploaded it to a server, then changed the login function to just print the data to a file. lol. It was easy. I took it down shortly after, but apparently someone found it and tried to login. lmao.
 

Joe88

[λ]
Global Moderator
Joined
Jan 6, 2008
Messages
12,738
Trophies
2
Age
36
XP
7,449
Country
United States
this isnt new, even sites like amazon are vulnerable
theres even an android app that will session hijack (you just have to be on the same internet connection as them)
 
Last edited by Joe88,
  • Like
Reactions: astronautlevel

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,044
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,020
Country
Portugal
I highly doubt Temp is vulnerable to SQL injection. Phising could also be used to get a password directly, there's no reason people would go out of the way to get the cookie instead.

Also, basically what @UniqueGeek said. There's no easy way around this because of how cookies work.
this.
 

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,044
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,020
Country
Portugal
Still, it is more secure than just letting people play with your account
Hell, I only use 2FA for Steam (cuz trades and market and all) and for the bank-related stuff. GBATemp is important, but I'm not important enough that anyone will bother hijacking my account just to piss me off soooo ya
 
  • Like
Reactions: Deleted User

Luckkill4u

4 guys in a car ( ͡° ͜ʖ ͡°)
Member
Joined
Jul 13, 2008
Messages
1,028
Trophies
1
Age
31
Location
Insomnia
Website
www.gbatemp.net
XP
1,141
Country
Canada
It's not really that hard, phishing. I once made a phishing site just to test it out. It was using Minecraft's website. I literally just downloaded the site and uploaded it to a server, then changed the login function to just print the data to a file. lol. It was easy. I took it down shortly after, but apparently someone found it and tried to login. lmao.
I was talking more about SQLi, Phishing is easy but also easy to spot.
 

migles

All my gbatemp friends are now mods, except for me
Member
Joined
Sep 19, 2013
Messages
8,033
Trophies
0
Location
Earth-chan
XP
5,299
Country
China
can't this be used on almost every fucking site that auto logins?
i mean, how else the auto login system works?, a cookie is deposited on your computer, the website reads it and aknoledges that it's you
cookies guarantees that autologin works even if you change your ip or country..

if you have the cookie, that means it's you...
there is only 2 ways i can think to prevent this, get rid of autologin or when user logs out (by using the logout) that cookie is discarted and you need to login again
 

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,044
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,020
Country
Portugal
What would people want to do with someone's GBAtemp account anyway? I mean there's really nothing they would be able to get out of it.
gotta get them users banned by posting on their behalf :D
 
D

Deleted User

Guest
If you get someone's cookies you can actually log into their account
And how would you get somebody';s cookies? If it is as simple as running a script or a chrome extention, sure that might be a problem. But it isn't a prblem when you have to be on the network or have to know the email. It's kinda a non-problem at that point.
 

Chary

Never sleeps
Chief Editor
Joined
Oct 2, 2012
Messages
12,355
Trophies
4
Age
27
Website
opencritic.com
XP
129,123
Country
United States
Two Factor Authentication? That could be implemented, I assume, but that can be annoying.
As much as I love GBAtemp, I'd rather be hacked than give out my phone number. After hearing the rash of account bans on PSN, I added 2FA to my PS4, and suddenly I'm getting all sorts of weird spam calls. I only call three people on my phone, so it's weird that out of the blue, my number seems to be so find-able. I don't trust that sort of thing.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • AncientBoi @ AncientBoi:
    I'm also saving 💰 . You know how much it is to just wash your clothes? pffffft
    +1
  • K3Nv2 @ K3Nv2:
    I saved 1k this month by being poor tbh
    +1
  • BigOnYa @ BigOnYa:
    Been eating Ramen all month, but my PC is badass!
    +1
  • K3Nv2 @ K3Nv2:
    Ramen still delicious don't care how much money I'll have
    +1
  • Minox @ Minox:
    I'm eating less, but mostly because I'm trying to avoid getting called heavy again during this year's health exam
    +1
  • Minox @ Minox:
    There's only so many ways they can say "You're fat by our country's standards"
    +1
  • K3Nv2 @ K3Nv2:
    My cholesterol was almost 350 so really stopped going out lol
  • AncientBoi @ AncientBoi:
    [uploads some 🐟 for you] :D @Minox
  • Minox @ Minox:
    I'll stick with my kimchi thank you
  • K3Nv2 @ K3Nv2:
    Triglycerides almost 900
  • Minox @ Minox:
    No idea what any of those things you mention are
    +1
  • K3Nv2 @ K3Nv2:
    Cholesterol and Triglycerides? Basically a way they measure fatty cells in your blood
  • AncientBoi @ AncientBoi:
    Cholesterol is sorta high, according to my doc
  • K3Nv2 @ K3Nv2:
    I've been taking fiber pills, eating more grapes, switched to wheat bread in hopes to lower it
    +1
  • BigOnYa @ BigOnYa:
    I like wheat bread, I even like the chunky wheat bread with pieces of whole grain in it.
  • K3Nv2 @ K3Nv2:
    Been getting this honey wheat bread from aldis pretty decent not very sweet to out do it
  • K3Nv2 @ K3Nv2:
    Me making any food at home is an improvement to how I use to be
    +1
  • BigOnYa @ BigOnYa:
    I have an bread machine and use it alot, better than breads you buy, but don't last as long, cause no bs preservatives
  • K3Nv2 @ K3Nv2:
    I got compliments about my weight loss and thought well guess I can pig out again now I'm the piggy
  • BigOnYa @ BigOnYa:
    My biggest prob is alcohol, definitely is fattening
  • K3Nv2 @ K3Nv2:
    I know when to stop at least honestly don't get those that go and go with food
  • BigOnYa @ BigOnYa:
    Or those that order 2 big macs , large fry, ice cream sundie, then a diet coke
  • K3Nv2 @ K3Nv2:
    I might get downing two big macs but nah that's it
    K3Nv2 @ K3Nv2: I might get downing two big macs but nah that's it