GBATemp Account Exploit

  • Thread starter Thread starter DavidRO99
  • Start date Start date
  • Views Views 6,208
  • Replies Replies 67
  • Likes Likes 2
Status
Not open for further replies.
And how would you get somebody';s cookies? If it is as simple as running a script or a chrome extention, sure that might be a problem. But it isn't a prblem when you have to be on the network or have to know the email. It's kinda a non-problem at that point.
Phising, posting on an exploitable forum site with an specially crafted img, sure, extensions, maybe badly coded extensions
 
This is completely standard behaviour and not really an issue at all for most people. If your browser didn't save session tokens then you'd constantly be manually re-authenticating with the site, which would be an undeniable pain in the ass.

Feel free to just block cookies from this domain if it's a problem for you though.
 
Security issues should not be discussed in an open forum to prevent giving nefarious people bad ideas. Always direct security issues to the admins.
Though in this particular case I think it can be argued whether this is a security issue or not.
 
Security issues should not be discussed in an open forum to prevent giving nefarious people bad ideas. Always direct security issues to the admins.
Though in this particular case I think it can be argued whether this is a security issue or not.
I'm going to add to this for people who do find a security bug. Report it to the whoever runs it, but make sure to give them a suitable time frame to fix it and release the bug if they don't. It's dangerous if bugs go unfixed, and many companies just won't take it seriously until it's public knowledge.
 
  • Like
Reactions: astronautlevel
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum